Microsoft Entra ID (formerly Azure AD) Policies.authorization Policy API

The policies.authorizationPolicy API from Microsoft Entra ID (formerly Azure AD) — 1 operation(s) for policies.authorizationpolicy.

Operations 3

GET /policies/authorizationPolicy Get authorizationPolicy #
PATCH /policies/authorizationPolicy Update authorizationPolicy #
DELETE /policies/authorizationPolicy Delete navigation property authorizationPolicy for policies #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/azure-ad-policies-authorizationpolicy-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

azure-ad-policies-authorizationpolicy-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity.SignIns Policies.authorization Policy API
  version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
  description: Core
security:
- azureaadv2: []
tags:
- name: policies.authorizationPolicy
paths:
  /policies/authorizationPolicy:
    get:
      tags:
      - policies.authorizationPolicy
      summary: Get authorizationPolicy
      description: Retrieve the properties of an authorizationPolicy object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/authorizationpolicy-get?view=graph-rest-1.0
      operationId: policy_GetAuthorizationPolicy
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.authorizationPolicy'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - policies.authorizationPolicy
      summary: Update authorizationPolicy
      description: Update the properties of an authorizationPolicy object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/authorizationpolicy-update?view=graph-rest-1.0
      operationId: policy_UpdateAuthorizationPolicy
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.authorizationPolicy'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.authorizationPolicy'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - policies.authorizationPolicy
      summary: Delete navigation property authorizationPolicy for policies
      operationId: policy_DeleteAuthorizationPolicy
      parameters:
      - name: If-Match
        in: header
        description: ETag
        style: simple
        schema:
          type: string
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
components:
  schemas:
    microsoft.graph.allowInvitesFrom:
      title: allowInvitesFrom
      enum:
      - none
      - adminsAndGuestInviters
      - adminsGuestInvitersAndAllMembers
      - everyone
      - unknownFutureValue
      type: string
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type:
          - string
          - 'null'
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
      additionalProperties:
        type: object
    microsoft.graph.ODataErrors.ODataError:
      required:
      - error
      type: object
      properties:
        error:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
      additionalProperties:
        type: object
    microsoft.graph.entity:
      title: entity
      type: object
      properties:
        id:
          type: string
          description: The unique identifier for an entity. Read-only.
      additionalProperties:
        type: object
    microsoft.graph.defaultUserRolePermissions:
      title: defaultUserRolePermissions
      type: object
      properties:
        allowedToCreateApps:
          type: boolean
          description: Indicates whether the default user role can create applications. This setting corresponds to the Users can register applications setting in the User settings menu in the Microsoft Entra admin center.
        allowedToCreateSecurityGroups:
          type: boolean
          description: 'Indicates whether the default user role can create security groups. This setting corresponds to the following menus in the Microsoft Entra admin center:  The Users can create security groups in Microsoft Entra admin centers, API or PowerShell setting in the Group settings menu.  Users can create security groups setting in the User settings menu.'
        allowedToCreateTenants:
          type:
          - boolean
          - 'null'
          description: Indicates whether the default user role can create tenants. This setting corresponds to the Restrict non-admin users from creating tenants setting in the User settings menu in the Microsoft Entra admin center.  When this setting is false, users assigned the Tenant Creator role can still create tenants.
        allowedToReadBitlockerKeysForOwnedDevice:
          type:
          - boolean
          - 'null'
          description: Indicates whether the registered owners of a device can read their own BitLocker recovery keys with default user role.
        allowedToReadOtherUsers:
          type: boolean
          description: Indicates whether the default user role can read other users. DO NOT SET THIS VALUE TO false.
        permissionGrantPoliciesAssigned:
          type: array
          items:
            type:
            - string
            - 'null'
          description: Indicates if user consent to apps is allowed, and if it is, which permission to grant consent and which app consent policy (permissionGrantPolicy) govern the permission for users to grant consent. Value should be in the format managePermissionGrantsForSelf.{id}, where {id} is the id of a built-in or custom app consent policy. An empty list indicates user consent to apps is disabled.
      additionalProperties:
        type: object
    microsoft.graph.policyBase:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.directoryObject'
      - title: policyBase
        type: object
        properties:
          description:
            type:
            - string
            - 'null'
            description: Description for this policy. Required.
          displayName:
            type:
            - string
            - 'null'
            description: Display name for this policy. Required.
        additionalProperties:
          type: object
    microsoft.graph.ODataErrors.InnerError:
      type: object
      additionalProperties:
        type: object
      description: The structure of this object is service-specific
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
        additionalProperties:
          type: object
    microsoft.graph.authorizationPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.policyBase'
      - title: authorizationPolicy
        type: object
        properties:
          allowedToSignUpEmailBasedSubscriptions:
            type: boolean
            description: Indicates whether users can sign up for email based subscriptions.
          allowedToUseSSPR:
            type: boolean
            description: Indicates whether administrators of the tenant can use the Self-Service Password Reset (SSPR). For more information, see Self-service password reset for administrators.
          allowEmailVerifiedUsersToJoinOrganization:
            type: boolean
            description: Indicates whether a user can join the tenant by email validation.
          allowInvitesFrom:
            $ref: '#/components/schemas/microsoft.graph.allowInvitesFrom'
          allowUserConsentForRiskyApps:
            type:
            - boolean
            - 'null'
            description: Indicates whether user consent for risky apps is allowed. We recommend keeping allowUserConsentForRiskyApps as false. Default value is false.
          blockMsolPowerShell:
            type:
            - boolean
            - 'null'
            description: To disable the use of MSOL PowerShell, set this property to true. This also disables user-based access to the legacy service endpoint used by MSOL PowerShell. This doesn't affect Microsoft Entra Connect or Microsoft Graph.
          defaultUserRolePermissions:
            $ref: '#/components/schemas/microsoft.graph.defaultUserRolePermissions'
          guestUserRoleId:
            pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
            type:
            - string
            - 'null'
            description: 'Represents role templateId for the role that should be granted to guests. Currently following roles are supported:  User (a0b1b346-4d3e-4e8b-98f8-753987be4970), Guest User (10dae51f-b6af-4016-8d66-8c2a99b929b3), and Restricted Guest User (2af84b1e-32c8-42b7-82bc-daa82404023b).'
            format: uuid
        additionalProperties:
          type: object
  responses:
    error:
      description: error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
  securitySchemes:
    azureaadv2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
          tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
          scopes: {}