Microsoft Entra ID (formerly Azure AD) Service Principals.app Role Assignment API
The servicePrincipals.appRoleAssignment API from Microsoft Entra ID (formerly Azure AD) — 6 operation(s) for serviceprincipals.approleassignment.
The servicePrincipals.appRoleAssignment API from Microsoft Entra ID (formerly Azure AD) — 6 operation(s) for serviceprincipals.approleassignment.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/azure-ad-serviceprincipals-approleassignment-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Applications Service Principals.app Role Assignment API
version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
description: Core
security:
- azureaadv2: []
tags:
- name: servicePrincipals.appRoleAssignment
paths:
/servicePrincipals/{servicePrincipal-id}/appRoleAssignedTo:
get:
tags:
- servicePrincipals.appRoleAssignment
summary: Get appRoleAssignment
description: Read the properties and relationships of an appRoleAssignment object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/serviceprincipal-list-approleassignedto?view=graph-rest-1.0
operationId: servicePrincipal_ListAppRoleAssignedTo
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- $ref: '#/components/parameters/top'
- $ref: '#/components/parameters/skip'
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/count'
- name: $orderby
in: query
description: Order items by property values
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
$ref: '#/components/responses/microsoft.graph.appRoleAssignmentCollectionResponse'
default:
$ref: '#/components/responses/error'
x-ms-pageable:
nextLinkName: '@odata.nextLink'
operationName: listMore
x-ms-docs-operation-type: operation
post:
tags:
- servicePrincipals.appRoleAssignment
summary: Grant an appRoleAssignment for a service principal
description: 'Assign an app role for a resource service principal, to a user, group, or client service principal. App roles that are assigned to service principals are also known as application permissions. Application permissions can be granted directly with app role assignments, or through a consent experience. To grant an app role assignment, you need three identifiers:'
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/serviceprincipal-post-approleassignedto?view=graph-rest-1.0
operationId: servicePrincipal_CreateAppRoleAssignedTo
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
requestBody:
description: New navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
required: true
responses:
2XX:
description: Created navigation property.
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/servicePrincipals/{servicePrincipal-id}/appRoleAssignedTo/{appRoleAssignment-id}:
get:
tags:
- servicePrincipals.appRoleAssignment
summary: Get appRoleAssignment
description: Read the properties and relationships of an appRoleAssignment object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/approleassignment-get?view=graph-rest-1.0
operationId: servicePrincipal_GetAppRoleAssignedTo
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: appRoleAssignment-id
in: path
description: The unique identifier of appRoleAssignment
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: appRoleAssignment
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- servicePrincipals.appRoleAssignment
summary: Update the navigation property appRoleAssignedTo in servicePrincipals
operationId: servicePrincipal_UpdateAppRoleAssignedTo
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: appRoleAssignment-id
in: path
description: The unique identifier of appRoleAssignment
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: appRoleAssignment
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- servicePrincipals.appRoleAssignment
summary: Delete appRoleAssignedTo
description: Deletes an appRoleAssignment that a user, group, or client service principal has been granted for a resource service principal.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/serviceprincipal-delete-approleassignedto?view=graph-rest-1.0
operationId: servicePrincipal_DeleteAppRoleAssignedTo
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: appRoleAssignment-id
in: path
description: The unique identifier of appRoleAssignment
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: appRoleAssignment
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/servicePrincipals/{servicePrincipal-id}/appRoleAssignedTo/$count:
get:
tags:
- servicePrincipals.appRoleAssignment
summary: Get the number of the resource
operationId: servicePrincipal.appRoleAssignedTo_GetCount
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
responses:
2XX:
$ref: '#/components/responses/ODataCountResponse'
default:
$ref: '#/components/responses/error'
/servicePrincipals/{servicePrincipal-id}/appRoleAssignments:
get:
tags:
- servicePrincipals.appRoleAssignment
summary: Get appRoleAssignment
description: Read the properties and relationships of an appRoleAssignment object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/serviceprincipal-list-approleassignments?view=graph-rest-1.0
operationId: servicePrincipal_ListAppRoleAssignment
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: ConsistencyLevel
in: header
description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
style: simple
schema:
type: string
examples:
example-1:
description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
value: eventual
- $ref: '#/components/parameters/top'
- $ref: '#/components/parameters/skip'
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/count'
- name: $orderby
in: query
description: Order items by property values
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
$ref: '#/components/responses/microsoft.graph.appRoleAssignmentCollectionResponse'
default:
$ref: '#/components/responses/error'
x-ms-pageable:
nextLinkName: '@odata.nextLink'
operationName: listMore
x-ms-docs-operation-type: operation
post:
tags:
- servicePrincipals.appRoleAssignment
summary: Grant an appRoleAssignment to a service principal
description: 'Assign an app role to a client service principal. App roles that are assigned to service principals are also known as application permissions. Application permissions can be granted directly with app role assignments, or through a consent experience. To grant an app role assignment to a client service principal, you need three identifiers:'
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/serviceprincipal-post-approleassignments?view=graph-rest-1.0
operationId: servicePrincipal_CreateAppRoleAssignment
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
requestBody:
description: New navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
required: true
responses:
2XX:
description: Created navigation property.
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/servicePrincipals/{servicePrincipal-id}/appRoleAssignments/{appRoleAssignment-id}:
get:
tags:
- servicePrincipals.appRoleAssignment
summary: Get appRoleAssignment
description: Read the properties and relationships of an appRoleAssignment object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/approleassignment-get?view=graph-rest-1.0
operationId: servicePrincipal_GetAppRoleAssignment
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: appRoleAssignment-id
in: path
description: The unique identifier of appRoleAssignment
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: appRoleAssignment
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- servicePrincipals.appRoleAssignment
summary: Update the navigation property appRoleAssignments in servicePrincipals
operationId: servicePrincipal_UpdateAppRoleAssignment
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: appRoleAssignment-id
in: path
description: The unique identifier of appRoleAssignment
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: appRoleAssignment
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- servicePrincipals.appRoleAssignment
summary: Delete appRoleAssignment
description: Deletes an appRoleAssignment that a service principal has been granted. App roles which are assigned to service principals are also known as application permissions. Deleting an app role assignment for a service principal is equivalent to revoking the app-only permission grant.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/serviceprincipal-delete-approleassignments?view=graph-rest-1.0
operationId: servicePrincipal_DeleteAppRoleAssignment
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: appRoleAssignment-id
in: path
description: The unique identifier of appRoleAssignment
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: appRoleAssignment
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/servicePrincipals/{servicePrincipal-id}/appRoleAssignments/$count:
get:
tags:
- servicePrincipals.appRoleAssignment
summary: Get the number of the resource
operationId: servicePrincipal.appRoleAssignment_GetCount
parameters:
- name: servicePrincipal-id
in: path
description: The unique identifier of servicePrincipal
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: servicePrincipal
- name: ConsistencyLevel
in: header
description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
style: simple
schema:
type: string
examples:
example-1:
description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
value: eventual
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
responses:
2XX:
$ref: '#/components/responses/ODataCountResponse'
default:
$ref: '#/components/responses/error'
components:
responses:
error:
description: error
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
microsoft.graph.appRoleAssignmentCollectionResponse:
description: Retrieved collection
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignmentCollectionResponse'
ODataCountResponse:
description: The count of the resource
content:
text/plain:
schema:
$ref: '#/components/schemas/ODataCountResponse'
schemas:
microsoft.graph.ODataErrors.MainError:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
x-ms-primary-error-message: true
target:
type:
- string
- 'null'
details:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
innerError:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
additionalProperties:
type: object
microsoft.graph.directoryObject:
allOf:
- $ref: '#/components/schemas/microsoft.graph.entity'
- title: directoryObject
type: object
properties:
deletedDateTime:
pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
type:
- string
- 'null'
description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
format: date-time
additionalProperties:
type: object
ODataCountResponse:
type: integer
format: int32
microsoft.graph.ODataErrors.ODataError:
required:
- error
type: object
properties:
error:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
additionalProperties:
type: object
microsoft.graph.entity:
title: entity
type: object
properties:
id:
type: string
description: The unique identifier for an entity. Read-only.
additionalProperties:
type: object
microsoft.graph.appRoleAssignmentCollectionResponse:
title: Collection of appRoleAssignment
type: object
properties:
value:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
'@odata.nextLink':
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.ODataErrors.InnerError:
type: object
additionalProperties:
type: object
description: The structure of this object is service-specific
microsoft.graph.ODataErrors.ErrorDetails:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
target:
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.appRoleAssignment:
allOf:
- $ref: '#/components/schemas/microsoft.graph.directoryObject'
- title: appRoleAssignment
type: object
properties:
appRoleId:
pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
type: string
description: The identifier (id) for the app role that's assigned to the principal. This app role must be exposed in the appRoles property on the resource application's service principal (resourceId). If the resource application hasn't declared any app roles, a default app role ID of 00000000-0000-0000-0000-000000000000 can be specified to signal that the principal is assigned to the resource app without any specific app roles. Required on create.
format: uuid
createdDateTime:
pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
type:
- string
- 'null'
description: The time when the app role assignment was created. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only.
format: date-time
principalDisplayName:
type:
- string
- 'null'
description: The display name of the user, group, or service principal that was granted the app role assignment. Maximum length is 256 characters. Read-only. Supports $filter (eq and startswith).
principalId:
pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
type:
- string
- 'null'
description: The unique identifier (id) for the user, security group, or service principal being granted the app role. Security groups with dynamic memberships are supported. Required on create.
format: uuid
principalType:
type:
- string
- 'null'
description: The type of the assigned principal. This can either be User, Group, or ServicePrincipal. Read-only.
resourceDisplayName:
type:
- string
- 'null'
description: The display name of the resource app's service principal to which the assignment is made. Maximum length is 256 characters.
resourceId:
pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
type:
- string
- 'null'
description: The unique identifier (id) for the resource service principal for which the assignment is made. Required on create. Supports $filter (eq only).
format: uuid
additionalProperties:
type: object
parameters:
count:
name: $count
in: query
description: Include count of items
style: form
explode: false
schema:
type: boolean
filter:
name: $filter
in: query
description: Filter items by property values
style: form
explode: false
schema:
type: string
search:
name: $search
in: query
description: Search items by search phrases
style: form
explode: false
schema:
type: string
top:
name: $top
in: query
description: Show only the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
example: 50
skip:
name: $skip
in: query
description: Skip the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
securitySchemes:
azureaadv2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
scopes: {}