Microsoft Entra ID (formerly Azure AD) Identity Protection.risky User API
The identityProtection.riskyUser API from Microsoft Entra ID (formerly Azure AD) — 9 operation(s) for identityprotection.riskyuser.
The identityProtection.riskyUser API from Microsoft Entra ID (formerly Azure AD) — 9 operation(s) for identityprotection.riskyuser.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/azure-ad-identityprotection-riskyuser-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Identity.SignIns Identity Protection.risky User API
version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
description: Core
security:
- azureaadv2: []
tags:
- name: identityProtection.riskyUser
paths:
/identityProtection/riskyUsers:
get:
tags:
- identityProtection.riskyUser
summary: List riskyUsers
description: Get a list of the riskyUser objects and their properties.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/riskyuser-list?view=graph-rest-1.0
operationId: identityProtection_ListRiskyUser
parameters:
- $ref: '#/components/parameters/top'
- $ref: '#/components/parameters/skip'
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/count'
- name: $orderby
in: query
description: Order items by property values
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
$ref: '#/components/responses/microsoft.graph.riskyUserCollectionResponse'
default:
$ref: '#/components/responses/error'
x-ms-pageable:
nextLinkName: '@odata.nextLink'
operationName: listMore
x-ms-docs-operation-type: operation
post:
tags:
- identityProtection.riskyUser
summary: Create new navigation property to riskyUsers for identityProtection
operationId: identityProtection_CreateRiskyUser
requestBody:
description: New navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUser'
required: true
responses:
2XX:
description: Created navigation property.
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUser'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/identityProtection/riskyUsers/{riskyUser-id}:
get:
tags:
- identityProtection.riskyUser
summary: Get riskyUser
description: Read the properties and relationships of a riskyUser object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/riskyuser-get?view=graph-rest-1.0
operationId: identityProtection_GetRiskyUser
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUser'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- identityProtection.riskyUser
summary: Update the navigation property riskyUsers in identityProtection
operationId: identityProtection_UpdateRiskyUser
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUser'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUser'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- identityProtection.riskyUser
summary: Delete navigation property riskyUsers for identityProtection
operationId: identityProtection_DeleteRiskyUser
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/identityProtection/riskyUsers/{riskyUser-id}/history:
get:
tags:
- identityProtection.riskyUser
summary: List history of riskyUser
description: Get the riskyUserHistoryItems from the history navigation property.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/riskyuser-list-history?view=graph-rest-1.0
operationId: identityProtection.riskyUser_ListHistory
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- $ref: '#/components/parameters/top'
- $ref: '#/components/parameters/skip'
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/count'
- name: $orderby
in: query
description: Order items by property values
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
$ref: '#/components/responses/microsoft.graph.riskyUserHistoryItemCollectionResponse'
default:
$ref: '#/components/responses/error'
x-ms-pageable:
nextLinkName: '@odata.nextLink'
operationName: listMore
x-ms-docs-operation-type: operation
post:
tags:
- identityProtection.riskyUser
summary: Create new navigation property to history for identityProtection
operationId: identityProtection.riskyUser_CreateHistory
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
requestBody:
description: New navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
required: true
responses:
2XX:
description: Created navigation property.
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}:
get:
tags:
- identityProtection.riskyUser
summary: Get history from identityProtection
description: The activity related to user risk level change
operationId: identityProtection.riskyUser_GetHistory
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- name: riskyUserHistoryItem-id
in: path
description: The unique identifier of riskyUserHistoryItem
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUserHistoryItem
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- identityProtection.riskyUser
summary: Update the navigation property history in identityProtection
operationId: identityProtection.riskyUser_UpdateHistory
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- name: riskyUserHistoryItem-id
in: path
description: The unique identifier of riskyUserHistoryItem
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUserHistoryItem
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- identityProtection.riskyUser
summary: Delete navigation property history for identityProtection
operationId: identityProtection.riskyUser_DeleteHistory
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- name: riskyUserHistoryItem-id
in: path
description: The unique identifier of riskyUserHistoryItem
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUserHistoryItem
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/identityProtection/riskyUsers/{riskyUser-id}/history/$count:
get:
tags:
- identityProtection.riskyUser
summary: Get the number of the resource
operationId: identityProtection.riskyUser.history_GetCount
parameters:
- name: riskyUser-id
in: path
description: The unique identifier of riskyUser
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: riskyUser
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
responses:
2XX:
$ref: '#/components/responses/ODataCountResponse'
default:
$ref: '#/components/responses/error'
/identityProtection/riskyUsers/$count:
get:
tags:
- identityProtection.riskyUser
summary: Get the number of the resource
operationId: identityProtection.riskyUser_GetCount
parameters:
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
responses:
2XX:
$ref: '#/components/responses/ODataCountResponse'
default:
$ref: '#/components/responses/error'
/identityProtection/riskyUsers/microsoft.graph.confirmCompromised:
post:
tags:
- identityProtection.riskyUser
summary: Invoke action confirmCompromised
description: Confirm one or more riskyUser objects as compromised. This action sets the targeted user's risk level to high.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/riskyuser-confirmcompromised?view=graph-rest-1.0
operationId: identityProtection.riskyUser_confirmCompromised
requestBody:
description: Action parameters
content:
application/json:
schema:
type: object
properties:
userIds:
type: array
items:
type:
- string
- 'null'
additionalProperties:
type: object
required: true
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: action
/identityProtection/riskyUsers/microsoft.graph.confirmSafe:
post:
tags:
- identityProtection.riskyUser
summary: Invoke action confirmSafe
description: Confirm one or more riskyUser objects as safe. This action sets the targeted user's risk level to none.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/riskyuser-confirmsafe?view=graph-rest-1.0
operationId: identityProtection.riskyUser_confirmSafe
requestBody:
description: Action parameters
content:
application/json:
schema:
type: object
properties:
userIds:
type: array
items:
type:
- string
- 'null'
additionalProperties:
type: object
required: true
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: action
/identityProtection/riskyUsers/microsoft.graph.dismiss:
post:
tags:
- identityProtection.riskyUser
summary: Invoke action dismiss
description: Dismiss the risk of one or more riskyUser objects. This action sets the targeted user's risk level to none.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/riskyuser-dismiss?view=graph-rest-1.0
operationId: identityProtection.riskyUser_dismiss
requestBody:
description: Action parameters
content:
application/json:
schema:
type: object
properties:
userIds:
type: array
items:
type:
- string
- 'null'
additionalProperties:
type: object
required: true
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: action
components:
responses:
error:
description: error
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
microsoft.graph.riskyUserHistoryItemCollectionResponse:
description: Retrieved collection
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItemCollectionResponse'
microsoft.graph.riskyUserCollectionResponse:
description: Retrieved collection
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.riskyUserCollectionResponse'
ODataCountResponse:
description: The count of the resource
content:
text/plain:
schema:
$ref: '#/components/schemas/ODataCountResponse'
schemas:
microsoft.graph.riskState:
title: riskState
enum:
- none
- confirmedSafe
- remediated
- dismissed
- atRisk
- confirmedCompromised
- unknownFutureValue
type: string
microsoft.graph.ODataErrors.MainError:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
x-ms-primary-error-message: true
target:
type:
- string
- 'null'
details:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
innerError:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
additionalProperties:
type: object
ODataCountResponse:
type: integer
format: int32
microsoft.graph.riskyUserHistoryItemCollectionResponse:
title: Collection of riskyUserHistoryItem
type: object
properties:
value:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
'@odata.nextLink':
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.ODataErrors.InnerError:
type: object
additionalProperties:
type: object
description: The structure of this object is service-specific
microsoft.graph.ODataErrors.ODataError:
required:
- error
type: object
properties:
error:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
additionalProperties:
type: object
microsoft.graph.riskLevel:
title: riskLevel
enum:
- low
- medium
- high
- hidden
- none
- unknownFutureValue
type: string
microsoft.graph.ODataErrors.ErrorDetails:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
target:
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.entity:
title: entity
type: object
properties:
id:
type: string
description: The unique identifier for an entity. Read-only.
additionalProperties:
type: object
microsoft.graph.riskyUser:
allOf:
- $ref: '#/components/schemas/microsoft.graph.entity'
- title: riskyUser
type: object
properties:
isDeleted:
type:
- boolean
- 'null'
description: 'Indicates whether the user is deleted. The possible values are: true, false.'
isProcessing:
type:
- boolean
- 'null'
description: Indicates whether the backend is processing a user's risky state.
riskDetail:
$ref: '#/components/schemas/microsoft.graph.riskDetail'
riskLastUpdatedDateTime:
pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
type:
- string
- 'null'
description: The date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
format: date-time
riskLevel:
$ref: '#/components/schemas/microsoft.graph.riskLevel'
riskState:
$ref: '#/components/schemas/microsoft.graph.riskState'
userDisplayName:
type:
- string
- 'null'
description: Risky user display name.
userPrincipalName:
type:
- string
- 'null'
description: Risky user principal name.
history:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
description: The activity related to user risk level change
x-ms-navigationProperty: true
additionalProperties:
type: object
microsoft.graph.riskUserActivity:
title: riskUserActivity
type: object
properties:
detail:
$ref: '#/components/schemas/microsoft.graph.riskDetail'
riskEventTypes:
type: array
items:
type:
- string
- 'null'
description: The type of risk event detected.
additionalProperties:
type: object
microsoft.graph.riskDetail:
title: riskDetail
enum:
- none
- adminGeneratedTemporaryPassword
- userPerformedSecuredPasswordChange
- userPerformedSecuredPasswordReset
- adminConfirmedSigninSafe
- aiConfirmedSigninSafe
- userPassedMFADrivenByRiskBasedPolicy
- adminDismissedAllRiskForUser
- adminConfirmedSigninCompromised
- hidden
- adminConfirmedUserCompromised
- unknownFutureValue
- m365DAdminDismissedDetection
- adminConfirmedServicePrincipalCompromised
- adminDismissedAllRiskForServicePrincipal
- userChangedPasswordOnPremises
- adminDismissedRiskForSignIn
- adminConfirmedAccountSafe
- microsoftRevokedSessions
type: string
microsoft.graph.riskyUserCollectionResponse:
title: Collection of riskyUser
type: object
properties:
value:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.riskyUser'
'@odata.nextLink':
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.riskyUserHistoryItem:
allOf:
- $ref: '#/components/schemas/microsoft.graph.riskyUser'
- title: riskyUserHistoryItem
type: object
properties:
activity:
$ref: '#/components/schemas/microsoft.graph.riskUserActivity'
initiatedBy:
type:
- string
- 'null'
description: The ID of actor that does the operation.
userId:
type:
- string
- 'null'
description: The ID of the user.
additionalProperties:
type: object
parameters:
filter:
name: $filter
in: query
description: Filter items by property values
style: form
explode: false
schema:
type: string
search:
name: $search
in: query
description: Search items by search phrases
style: form
explode: false
schema:
type: string
count:
name: $count
in: query
description: Include count of items
style: form
explode: false
schema:
type: boolean
skip:
name: $skip
in: query
description: Skip the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
top:
name: $top
in: query
description: Show only the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
example: 50
securitySchemes:
azureaadv2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
scopes: {}