Microsoft Graph policies.conditionalAccessPolicy API

The policies.conditionalAccessPolicy API from Microsoft Graph — 3 operation(s) for policies.conditionalaccesspolicy.

Operations 6

GET /policies/conditionalAccessPolicies Microsoft Graph Get conditionalAccessPolicies from policies #
POST /policies/conditionalAccessPolicies Microsoft Graph Create new navigation property to conditionalAccessPolicies for policies #
GET /policies/conditionalAccessPolicies/{conditionalAccessPolicy-id} Microsoft Graph Get conditionalAccessPolicies from policies #
PATCH /policies/conditionalAccessPolicies/{conditionalAccessPolicy-id} Microsoft Graph Update the navigation property conditionalAccessPolicies in policies #
DELETE /policies/conditionalAccessPolicies/{conditionalAccessPolicy-id} Microsoft Graph Delete navigation property conditionalAccessPolicies for policies #
GET /policies/conditionalAccessPolicies/$count Microsoft Graph Get the number of the resource #

Documentation

📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/admin?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreementacceptance?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamsapp?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/applicationtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodspolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/certificatebasedauthconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/chat?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/communications-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/complianceapioverview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-externalconnection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contract?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/copilot-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/datapolicyoperation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-apps-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-device-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/directory?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domaindnsrecord?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domain?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/drive?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/education-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/employee-experience-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-external?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/filter-query-parameter
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/grouplifecyclepolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsetting?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsettingtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/identitycontainer?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/informationprotection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/invitation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/users?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/oauth2permissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/resourcespecificpermissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/place?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/planner-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/policy-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/print?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/privacy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/report?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/rolemanagement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/scopedrolemembership?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/search-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/serviceprincipal?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/shares?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sharepoint?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/solutions-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/filestorage?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscribedsku?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamwork?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/tenantrelationship?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/auth/auth-concepts
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/workplace?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sitepage?view=graph-rest-1.0

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/microsoft-graph-policies-conditionalaccesspolicy-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

microsoft-graph-policies-conditionalaccesspolicy-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Microsoft Graph Admin Admin.admin Policies.conditional Access Policy API
  description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID.

    This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations,

    site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements,

    SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.'
  version: 1.0.0
  contact:
    name: Microsoft Graph API Support
    url: https://developer.microsoft.com/graph
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph API v1.0 endpoint
tags:
- name: policies.conditionalAccessPolicy
  x-ms-docs-toc-type: page
paths:
  /policies/conditionalAccessPolicies:
    description: Provides operations to manage the conditionalAccessPolicies property of the microsoft.graph.policyRoot entity.
    get:
      tags:
      - policies.conditionalAccessPolicy
      summary: Microsoft Graph Get conditionalAccessPolicies from policies
      description: The custom rules that define an access scenario.
      operationId: policies.ListConditionalAccessPolicies
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.conditionalAccessPolicyCollectionResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - policies.conditionalAccessPolicy
      summary: Microsoft Graph Create new navigation property to conditionalAccessPolicies for policies
      operationId: policies.CreateConditionalAccessPolicies
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/conditionalAccessPolicies/{conditionalAccessPolicy-id}:
    description: Provides operations to manage the conditionalAccessPolicies property of the microsoft.graph.policyRoot entity.
    parameters:
    - name: conditionalAccessPolicy-id
      in: path
      description: The unique identifier of conditionalAccessPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: conditionalAccessPolicy
    get:
      tags:
      - policies.conditionalAccessPolicy
      summary: Microsoft Graph Get conditionalAccessPolicies from policies
      description: The custom rules that define an access scenario.
      operationId: policies.GetConditionalAccessPolicies
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - policies.conditionalAccessPolicy
      summary: Microsoft Graph Update the navigation property conditionalAccessPolicies in policies
      operationId: policies.UpdateConditionalAccessPolicies
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - policies.conditionalAccessPolicy
      summary: Microsoft Graph Delete navigation property conditionalAccessPolicies for policies
      operationId: policies.DeleteConditionalAccessPolicies
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/conditionalAccessPolicies/$count:
    description: Provides operations to count the resources in the collection.
    get:
      tags:
      - policies.conditionalAccessPolicy
      summary: Microsoft Graph Get the number of the resource
      operationId: policies.conditionalAccessPolicies.GetCount-2c66
      parameters:
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
components:
  schemas:
    ODataCountResponse:
      type: integer
      format: int32
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type: string
          nullable: true
    microsoft.graph.conditionalAccessLocations:
      title: conditionalAccessLocations
      required:
      - '@odata.type'
      type: object
      properties:
        excludeLocations:
          type: array
          items:
            type: string
          description: Location IDs excluded from scope of policy.
        includeLocations:
          type: array
          items:
            type: string
          description: Location IDs in scope of policy unless explicitly excluded, All, or AllTrusted.
        '@odata.type':
          type: string
    microsoft.graph.cloudAppSecuritySessionControlType:
      title: cloudAppSecuritySessionControlType
      enum:
      - mcasConfigured
      - monitorOnly
      - blockDownloads
      - unknownFutureValue
      type: string
    microsoft.graph.conditionalAccessGuestsOrExternalUsers:
      title: conditionalAccessGuestsOrExternalUsers
      required:
      - '@odata.type'
      type: object
      properties:
        externalTenants:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenants'
          - type: object
            nullable: true
          description: The tenant IDs of the selected types of external users. Either all B2B tenant or a collection of tenant IDs. External tenants can be specified only when the property guestOrExternalUserTypes isn't null or an empty String.
        guestOrExternalUserTypes:
          $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestOrExternalUserTypes'
        '@odata.type':
          type: string
    microsoft.graph.cloudAppSecuritySessionControl:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl'
      - title: cloudAppSecuritySessionControl
        required:
        - '@odata.type'
        type: object
        properties:
          cloudAppSecurityType:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControlType'
            - type: object
              nullable: true
            description: 'The possible values are: mcasConfigured, monitorOnly, blockDownloads, unknownFutureValue. For more information, see Deploy Conditional Access App Control for featured apps.'
          '@odata.type':
            type: string
            default: '#microsoft.graph.cloudAppSecuritySessionControl'
      x-ms-discriminator-value: '#microsoft.graph.cloudAppSecuritySessionControl'
    microsoft.graph.authenticationStrengthPolicyType:
      title: authenticationStrengthPolicyType
      enum:
      - builtIn
      - custom
      - unknownFutureValue
      type: string
    microsoft.graph.signInFrequencySessionControl:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl'
      - title: signInFrequencySessionControl
        required:
        - '@odata.type'
        type: object
        properties:
          authenticationType:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.signInFrequencyAuthenticationType'
            - type: object
              nullable: true
            description: The possible values are primaryAndSecondaryAuthentication, secondaryAuthentication, unknownFutureValue. This property isn't required when using frequencyInterval with the value of timeBased.
          frequencyInterval:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.signInFrequencyInterval'
            - type: object
              nullable: true
            description: The possible values are timeBased, everyTime, unknownFutureValue. Sign-in frequency of everyTime is available for risky users, risky sign-ins, and Intune device enrollment. For more information, see Require reauthentication every time.
          type:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.signinFrequencyType'
            - type: object
              nullable: true
            description: 'The possible values are: days, hours.'
          value:
            maximum: 2147483647
            minimum: -2147483648
            type: number
            description: The number of days or hours.
            format: int32
            nullable: true
          '@odata.type':
            type: string
            default: '#microsoft.graph.signInFrequencySessionControl'
      x-ms-discriminator-value: '#microsoft.graph.signInFrequencySessionControl'
    microsoft.graph.conditionalAccessAuthenticationFlows:
      title: conditionalAccessAuthenticationFlows
      required:
      - '@odata.type'
      type: object
      properties:
        transferMethods:
          $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods'
        '@odata.type':
          type: string
    microsoft.graph.conditionalAccessExternalTenants:
      title: conditionalAccessExternalTenants
      required:
      - '@odata.type'
      type: object
      properties:
        membershipKind:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenantsMembershipKind'
          - type: object
            nullable: true
          description: 'The membership kind. The possible values are: all, enumerated, unknownFutureValue. The enumerated member references an conditionalAccessEnumeratedExternalTenants object.'
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.conditionalAccessAllExternalTenants': '#/components/schemas/microsoft.graph.conditionalAccessAllExternalTenants'
          '#microsoft.graph.conditionalAccessEnumeratedExternalTenants': '#/components/schemas/microsoft.graph.conditionalAccessEnumeratedExternalTenants'
    microsoft.graph.applicationEnforcedRestrictionsSessionControl:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl'
      - title: applicationEnforcedRestrictionsSessionControl
        required:
        - '@odata.type'
        type: object
        properties:
          '@odata.type':
            type: string
            default: '#microsoft.graph.applicationEnforcedRestrictionsSessionControl'
      x-ms-discriminator-value: '#microsoft.graph.applicationEnforcedRestrictionsSessionControl'
    microsoft.graph.filterMode:
      title: filterMode
      enum:
      - include
      - exclude
      type: string
    microsoft.graph.persistentBrowserSessionControl:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl'
      - title: persistentBrowserSessionControl
        required:
        - '@odata.type'
        type: object
        properties:
          mode:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionMode'
            - type: object
              nullable: true
            description: 'The possible values are: always, never.'
          '@odata.type':
            type: string
            default: '#microsoft.graph.persistentBrowserSessionControl'
      x-ms-discriminator-value: '#microsoft.graph.persistentBrowserSessionControl'
    microsoft.graph.ODataErrors.InnerError:
      title: InnerError
      required:
      - '@odata.type'
      type: object
      properties:
        request-id:
          type: string
          description: Request Id as tracked internally by the service
          nullable: true
        client-request-id:
          type: string
          description: Client request Id as sent by the client application.
          nullable: true
        date:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date when the error occured.
          format: date-time
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.conditionalAccessClientApplications:
      title: conditionalAccessClientApplications
      required:
      - '@odata.type'
      type: object
      properties:
        excludeServicePrincipals:
          type: array
          items:
            type: string
          description: Service principal IDs excluded from the policy scope.
        includeServicePrincipals:
          type: array
          items:
            type: string
          description: Service principal IDs included in the policy scope, or ServicePrincipalsInMyTenant.
        servicePrincipalFilter:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter'
          - type: object
            nullable: true
          description: Filter that defines the dynamic-servicePrincipal-syntax rule to include/exclude service principals. A filter can use custom security attributes to include/exclude service principals.
        '@odata.type':
          type: string
    microsoft.graph.conditionalAccessSessionControl:
      title: conditionalAccessSessionControl
      required:
      - '@odata.type'
      type: object
      properties:
        isEnabled:
          type: boolean
          description: Specifies whether the session control is enabled.
          nullable: true
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.applicationEnforcedRestrictionsSessionControl': '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl'
          '#microsoft.graph.cloudAppSecuritySessionControl': '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl'
          '#microsoft.graph.persistentBrowserSessionControl': '#/components/schemas/microsoft.graph.persistentBrowserSessionControl'
          '#microsoft.graph.secureSignInSessionControl': '#/components/schemas/microsoft.graph.secureSignInSessionControl'
          '#microsoft.graph.signInFrequencySessionControl': '#/components/schemas/microsoft.graph.signInFrequencySessionControl'
    microsoft.graph.authenticationCombinationConfiguration:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: authenticationCombinationConfiguration
        required:
        - '@odata.type'
        type: object
        properties:
          appliesToCombinations:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes'
            description: Which authentication method combinations this configuration applies to. Must be an allowedCombinations object, part of the authenticationStrengthPolicy. The only possible value for fido2combinationConfigurations is 'fido2'.
          '@odata.type':
            type: string
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.fido2CombinationConfiguration': '#/components/schemas/microsoft.graph.fido2CombinationConfiguration'
            '#microsoft.graph.x509CertificateCombinationConfiguration': '#/components/schemas/microsoft.graph.x509CertificateCombinationConfiguration'
    microsoft.graph.conditionalAccessInsiderRiskLevels:
      title: conditionalAccessInsiderRiskLevels
      enum:
      - minor
      - moderate
      - elevated
      - unknownFutureValue
      type: string
      x-ms-enum-flags:
        isFlags: true
    microsoft.graph.signInFrequencyInterval:
      title: signInFrequencyInterval
      enum:
      - timeBased
      - everyTime
      - unknownFutureValue
      type: string
    microsoft.graph.secureSignInSessionControl:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl'
      - title: secureSignInSessionControl
        required:
        - '@odata.type'
        type: object
        properties:
          '@odata.type':
            type: string
            default: '#microsoft.graph.secureSignInSessionControl'
      x-ms-discriminator-value: '#microsoft.graph.secureSignInSessionControl'
    microsoft.graph.conditionalAccessApplications:
      title: conditionalAccessApplications
      required:
      - '@odata.type'
      type: object
      properties:
        applicationFilter:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter'
          - type: object
            nullable: true
          description: Filter that defines the dynamic-application-syntax rule to include/exclude cloud applications. A filter can use custom security attributes to include/exclude applications.
        excludeApplications:
          type: array
          items:
            type: string
          description: 'Can be one of the following:  The list of client IDs (appId) explicitly excluded from the policy. Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite  MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals'
        includeApplications:
          type: array
          items:
            type: string
          description: 'Can be one of the following:  The list of client IDs (appId) the policy applies to, unless explicitly excluded (in excludeApplications)  All  Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite  MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals'
        includeAuthenticationContextClassReferences:
          type: array
          items:
            type: string
        includeUserActions:
          type: array
          items:
            type: string
          description: User actions to include. Supported values are urn:user:registersecurityinfo and urn:user:registerdevice
        '@odata.type':
          type: string
    microsoft.graph.authenticationMethodModes:
      title: authenticationMethodModes
      enum:
      - password
      - voice
      - hardwareOath
      - softwareOath
      - sms
      - fido2
      - windowsHelloForBusiness
      - microsoftAuthenticatorPush
      - deviceBasedPush
      - temporaryAccessPassOneTime
      - temporaryAccessPassMultiUse
      - email
      - x509CertificateSingleFactor
      - x509CertificateMultiFactor
      - federatedSingleFactor
      - federatedMultiFactor
      - unknownFutureValue
      type: string
      x-ms-enum-flags:
        isFlags: true
    microsoft.graph.conditionalAccessSessionControls:
      title: conditionalAccessSessionControls
      required:
      - '@odata.type'
      type: object
      properties:
        applicationEnforcedRestrictions:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl'
          - type: object
            nullable: true
          description: Session control to enforce application restrictions. Only Exchange Online and Sharepoint Online support this session control.
        cloudAppSecurity:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl'
          - type: object
            nullable: true
          description: Session control to apply cloud app security.
        disableResilienceDefaults:
          type: boolean
          description: Session control that determines whether it is acceptable for Microsoft Entra ID to extend existing sessions based on information collected prior to an outage or not.
          nullable: true
        persistentBrowser:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionControl'
          - type: object
            nullable: true
          description: Session control to define whether to persist cookies or not. All apps should be selected for this session control to work correctly.
        secureSignInSession:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.secureSignInSessionControl'
          - type: object
            nullable: true
        signInFrequency:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.signInFrequencySessionControl'
          - type: object
            nullable: true
          description: Session control to enforce signin frequency.
        '@odata.type':
          type: string
    microsoft.graph.conditionalAccessPolicyCollectionResponse:
      title: Collection of conditionalAccessPolicy
      type: object
      allOf:
      - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
      - type: object
        properties:
          value:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy'
    microsoft.graph.persistentBrowserSessionMode:
      title: persistentBrowserSessionMode
      enum:
      - always
      - never
      type: string
    microsoft.graph.signInFrequencyAuthenticationType:
      title: signInFrequencyAuthenticationType
      enum:
      - primaryAndSecondaryAuthentication
      - secondaryAuthentication
      - unknownFutureValue
      type: string
    microsoft.graph.conditionalAccessPolicyState:
      title: conditionalAccessPolicyState
      enum:
      - enabled
      - disabled
      - enabledForReportingButNotEnforced
      type: string
    microsoft.graph.conditionalAccessUsers:
      title: conditionalAccessUsers
      required:
      - '@odata.type'
      type: object
      properties:
        excludeGroups:
          type: array
          items:
            type: string
          description: Group IDs excluded from scope of policy.
        excludeGuestsOrExternalUsers:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers'
          - type: object
            nullable: true
          description: Internal guests or external users excluded from the policy scope. Optionally populated.
        excludeRoles:
          type: array
          items:
            type: string
          description: Role IDs excluded from scope of policy.
        excludeUsers:
          type: array
          items:
            type: string
          description: User IDs excluded from scope of policy and/or GuestsOrExternalUsers.
        includeGroups:
          type: array
          items:
            type: string
          description: Group IDs in scope of policy unless explicitly excluded.
        includeGuestsOrExternalUsers:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers'
          - type: object
            nullable: true
          description: Internal guests or external users included in the policy scope. Optionally populated.
        includeRoles:
          type: array
          items:
            type: string
          description: Role IDs in scope of policy unless explicitly excluded.
        includeUsers:
          type: array
          items:
            type: string
          description: User IDs in scope of policy unless explicitly excluded, None, All, or GuestsOrExternalUsers.
        '@odata.type':
          type: string
    microsoft.graph.conditionalAccessGrantControl:
      title: conditionalAccessGrantControl
      enum:
      - block
      - mfa
      - compliantDevice
      - domainJoinedDevice
      - approvedApplication
      - compliantApplication
      - passwordChange
      - unknownFutureValue
      type: string
    microsoft.graph.conditionalAccessTransferMethods:
      title: conditionalAccessTransferMethods
      enum:
      - none
      - deviceCodeFlow
      - authenticationTransfer
      - unknownFutureValue
      type: string
      x-ms-enum-flags:
        isFlags: true
    microsoft.graph.conditionalAccessGuestOrExternalUserTypes:
      title: conditionalAccessGuestOrExternalUserTypes
      enum:
      - none
      - internalGuest
      - b2bCollaborationGuest
      - b2bCollaborationMember
      - b2bDirectConnectUser
      - otherExternalUser
      - serviceProvider
      - unknownFutureValue
      type: string
      x-ms-enum-flags:
        isFlags: true
    microsoft.graph.conditionalAccessDevices:
      title: conditionalAccessDevices
      required:
      - '@odata.type'
      type: object
      properties:
        deviceFilter:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter'
          - type: object
            nullable: true
          description: Filter that defines the dynamic-device-syntax rule to include/exclude devices. A filter can use device properties (such as extension attributes) to include/exclude them.
        '@odata.type':
          type: string
    microsoft.graph.signinFrequencyType:
      title: signinFrequencyType
      enum:
      - days
      - hours
      type: string
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type: string
          nullable: true
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
    microsoft.graph.conditionalAccessFilter:
      title: conditionalAccessFilter
      required:
      - '@odata.type'
      type: object
      properties:
        mode:
          $ref: '#/components/schemas/microsoft.graph.filterMode'
        rule:
          type: string
          description: Rule syntax is similar to that used for membership rules for groups in Microsoft Entra ID. For details, see rules with multiple expressions
        '@odata.type':
          type: string
    microsoft.graph.conditionalAccessClientApp:
      title: conditionalAccessClientApp
      enum:
      - all
      - browser
      - mobileAppsAndDesktopClients
      - exchangeActiveSync
      - easSupported
      - other
      - unknownFutureValue
      type: string
    microsoft.graph.authenticationStrengthPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: authenticationStrengthPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          allowedCombinations:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes'
            description: A collection of authentication method modes that are required be used to satify this authentication strength.
          createdDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The datetime when this policy was created.
            format: date-time
          description:
            type: string
            description: The human-readable description of this policy.
            nullable: true
          displayName:
            type: string
            description: The human-readable display name of this policy. Supports $filter (eq, ne, not , and in).
          modifiedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The datetime when this policy was last modified.
            format: date-time
          policyType:
            $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyType'
          requirementsSatisfied:
            $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRequirements'
          combinationConfigurations:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration'
            description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.authenticationStrengthPolicy'
    microsoft.graph.riskLevel:
      title: riskLevel
      enum:
      - low
      - medium
      - high
      - hidden
      - none
      - unknownFutureValue
      type: string
    microsoft.graph.authenticationStrengthRequirements:
      title: authenticationStrengthRequirements
      enum:
      - none
      - mfa
      - unknownFutureValue
      type: string
      x-ms-enum-flags:
        isFlags: true
    microsoft.graph.conditionalAccessConditionSet:
      title: conditionalAccessConditionSet
      required:
      - '@odata.type'
      type: object
      properties:
        applications:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessApplications'
          - type: object
            nullable: true
          description: Applications and user actions included 

# --- truncated at 32 KB (163 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/microsoft-graph/refs/heads/main/openapi/microsoft-graph-policies-conditionalaccesspolicy-api-openapi.yml