Microsoft Graph policies.permissionGrantPolicy API

The policies.permissionGrantPolicy API from Microsoft Graph — 9 operation(s) for policies.permissiongrantpolicy.

Operations 18

GET /policies/permissionGrantPolicies Microsoft Graph List permissionGrantPolicies #
POST /policies/permissionGrantPolicies Microsoft Graph Create permissionGrantPolicy #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id} Microsoft Graph Get permissionGrantPolicy #
PATCH /policies/permissionGrantPolicies/{permissionGrantPolicy-id} Microsoft Graph Update permissionGrantPolicy #
DELETE /policies/permissionGrantPolicies/{permissionGrantPolicy-id} Microsoft Graph Delete permissionGrantPolicy #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes Microsoft Graph List excludes collection of permissionGrantPolicy #
POST /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes Microsoft Graph Create permissionGrantConditionSet in excludes collection of permissionGrantPolicy #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes/{permissionGrantConditionSet-id} Microsoft Graph Get excludes from policies #
PATCH /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes/{permissionGrantConditionSet-id} Microsoft Graph Update the navigation property excludes in policies #
DELETE /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes/{permissionGrantConditionSet-id} Microsoft Graph Delete permissionGrantConditionSet from excludes collection of permissionGrantPolicy #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes/$count Microsoft Graph Get the number of the resource #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes Microsoft Graph List includes collection of permissionGrantPolicy #
POST /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes Microsoft Graph Create permissionGrantConditionSet in includes collection of permissionGrantPolicy #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes/{permissionGrantConditionSet-id} Microsoft Graph Get includes from policies #
PATCH /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes/{permissionGrantConditionSet-id} Microsoft Graph Update the navigation property includes in policies #
DELETE /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes/{permissionGrantConditionSet-id} Microsoft Graph Delete permissionGrantConditionSet from includes collection of permissionGrantPolicy #
GET /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes/$count Microsoft Graph Get the number of the resource #
GET /policies/permissionGrantPolicies/$count Microsoft Graph Get the number of the resource #

Documentation

📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/admin?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreementacceptance?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamsapp?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/applicationtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodspolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/certificatebasedauthconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/chat?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/communications-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/complianceapioverview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-externalconnection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contract?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/copilot-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/datapolicyoperation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-apps-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-device-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/directory?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domaindnsrecord?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domain?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/drive?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/education-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/employee-experience-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-external?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/filter-query-parameter
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/grouplifecyclepolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsetting?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsettingtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/identitycontainer?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/informationprotection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/invitation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/users?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/oauth2permissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/resourcespecificpermissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/place?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/planner-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/policy-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/print?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/privacy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/report?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/rolemanagement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/scopedrolemembership?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/search-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/serviceprincipal?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/shares?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sharepoint?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/solutions-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/filestorage?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscribedsku?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamwork?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/tenantrelationship?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/auth/auth-concepts
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/workplace?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sitepage?view=graph-rest-1.0

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/microsoft-graph-policies-permissiongrantpolicy-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

microsoft-graph-policies-permissiongrantpolicy-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Microsoft Graph Admin Admin.admin Policies.permission Grant Policy API
  description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID.

    This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations,

    site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements,

    SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.'
  version: 1.0.0
  contact:
    name: Microsoft Graph API Support
    url: https://developer.microsoft.com/graph
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph API v1.0 endpoint
tags:
- name: policies.permissionGrantPolicy
  x-ms-docs-toc-type: page
paths:
  /policies/permissionGrantPolicies:
    description: Provides operations to manage the permissionGrantPolicies property of the microsoft.graph.policyRoot entity.
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph List permissionGrantPolicies
      description: Retrieve the list of permissionGrantPolicy objects.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-list?view=graph-rest-1.0
      operationId: policies.ListPermissionGrantPolicies
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.permissionGrantPolicyCollectionResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Create permissionGrantPolicy
      description: Creates a permissionGrantPolicy. A permission grant policy is used to describe the conditions under which permissions can be granted (for example, during application consent). After creating the permission grant policy, you can add include condition sets to add matching rules, and add exclude condition sets to add exclusion rules.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-post-permissiongrantpolicies?view=graph-rest-1.0
      operationId: policies.CreatePermissionGrantPolicies
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.permissionGrantPolicy'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantPolicy'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}:
    description: Provides operations to manage the permissionGrantPolicies property of the microsoft.graph.policyRoot entity.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Get permissionGrantPolicy
      description: Retrieve a single permissionGrantPolicy object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-get?view=graph-rest-1.0
      operationId: policies.GetPermissionGrantPolicies
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantPolicy'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Update permissionGrantPolicy
      description: Update properties of a  permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-update?view=graph-rest-1.0
      operationId: policies.UpdatePermissionGrantPolicies
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.permissionGrantPolicy'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantPolicy'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Delete permissionGrantPolicy
      description: Delete a permissionGrantPolicy object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-delete?view=graph-rest-1.0
      operationId: policies.DeletePermissionGrantPolicies
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes:
    description: Provides operations to manage the excludes property of the microsoft.graph.permissionGrantPolicy entity.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph List excludes collection of permissionGrantPolicy
      description: Retrieve the condition sets which are *excluded* in a permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-list-excludes?view=graph-rest-1.0
      operationId: policies.permissionGrantPolicies.ListExcludes
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.permissionGrantConditionSetCollectionResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Create permissionGrantConditionSet in excludes collection of permissionGrantPolicy
      description: Add conditions under which a permission grant event is *excluded* in a permission grant policy. You do this by adding a permissionGrantConditionSet to the excludes collection of a  permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-post-excludes?view=graph-rest-1.0
      operationId: policies.permissionGrantPolicies.CreateExcludes
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes/{permissionGrantConditionSet-id}:
    description: Provides operations to manage the excludes property of the microsoft.graph.permissionGrantPolicy entity.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    - name: permissionGrantConditionSet-id
      in: path
      description: The unique identifier of permissionGrantConditionSet
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantConditionSet
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Get excludes from policies
      description: Condition sets that are excluded in this permission grant policy. Automatically expanded on GET.
      operationId: policies.permissionGrantPolicies.GetExcludes
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Update the navigation property excludes in policies
      operationId: policies.permissionGrantPolicies.UpdateExcludes
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Delete permissionGrantConditionSet from excludes collection of permissionGrantPolicy
      description: Deletes a permissionGrantConditionSet from the excludes collection of a permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-delete-excludes?view=graph-rest-1.0
      operationId: policies.permissionGrantPolicies.DeleteExcludes
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/excludes/$count:
    description: Provides operations to count the resources in the collection.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Get the number of the resource
      operationId: policies.permissionGrantPolicies.excludes.GetCount-7507
      parameters:
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes:
    description: Provides operations to manage the includes property of the microsoft.graph.permissionGrantPolicy entity.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph List includes collection of permissionGrantPolicy
      description: Retrieve the condition sets which are *included* in a permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-list-includes?view=graph-rest-1.0
      operationId: policies.permissionGrantPolicies.ListIncludes
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.permissionGrantConditionSetCollectionResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Create permissionGrantConditionSet in includes collection of permissionGrantPolicy
      description: Add conditions under which a permission grant event is *included* in a permission grant policy. You do this by adding a permissionGrantConditionSet to the includes collection of a  permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-post-includes?view=graph-rest-1.0
      operationId: policies.permissionGrantPolicies.CreateIncludes
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes/{permissionGrantConditionSet-id}:
    description: Provides operations to manage the includes property of the microsoft.graph.permissionGrantPolicy entity.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    - name: permissionGrantConditionSet-id
      in: path
      description: The unique identifier of permissionGrantConditionSet
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantConditionSet
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Get includes from policies
      description: Condition sets that are included in this permission grant policy. Automatically expanded on GET.
      operationId: policies.permissionGrantPolicies.GetIncludes
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Update the navigation property includes in policies
      operationId: policies.permissionGrantPolicies.UpdateIncludes
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.permissionGrantConditionSet'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Delete permissionGrantConditionSet from includes collection of permissionGrantPolicy
      description: Deletes a permissionGrantConditionSet from the includes collection of a permissionGrantPolicy.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/permissiongrantpolicy-delete-includes?view=graph-rest-1.0
      operationId: policies.permissionGrantPolicies.DeleteIncludes
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /policies/permissionGrantPolicies/{permissionGrantPolicy-id}/includes/$count:
    description: Provides operations to count the resources in the collection.
    parameters:
    - name: permissionGrantPolicy-id
      in: path
      description: The unique identifier of permissionGrantPolicy
      required: true
      schema:
        type: string
      x-ms-docs-key-type: permissionGrantPolicy
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Get the number of the resource
      operationId: policies.permissionGrantPolicies.includes.GetCount-4a76
      parameters:
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
  /policies/permissionGrantPolicies/$count:
    description: Provides operations to count the resources in the collection.
    get:
      tags:
      - policies.permissionGrantPolicy
      summary: Microsoft Graph Get the number of the resource
      operationId: policies.permissionGrantPolicies.GetCount-86b8
      parameters:
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
components:
  schemas:
    ODataCountResponse:
      type: integer
      format: int32
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type: string
          nullable: true
    microsoft.graph.permissionType:
      title: permissionType
      enum:
      - delegatedUserConsentable
      - delegated
      - application
      type: string
    microsoft.graph.ODataErrors.InnerError:
      title: InnerError
      required:
      - '@odata.type'
      type: object
      properties:
        request-id:
          type: string
          description: Request Id as tracked internally by the service
          nullable: true
        client-request-id:
          type: string
          description: Client request Id as sent by the client application.
          nullable: true
        date:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date when the error occured.
          format: date-time
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.permissionGrantConditionSet:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: permissionGrantConditionSet
        required:
        - '@odata.type'
        type: object
        properties:
          clientApplicationIds:
            type: array
            items:
              type: string
              nullable: true
            description: A list of appId values for the client applications to match with, or a list with the single value all to match any client application. Default is the single value all.
          clientApplicationPublisherIds:
            type: array
            items:
              type: string
              nullable: true
            description: A list of Microsoft Partner Network (MPN) IDs for verified publishers of the client application, or a list with the single value all to match with client apps from any publisher. Default is the single value all.
          clientApplicationsFromVerifiedPublisherOnly:
            type: boolean
            description: Set to true to only match on client applications with a verified publisher. Set to false to match on any client app, even if it doesn't have a verified publisher. Default is false.
            nullable: true
          clientApplicationTenantIds:
            type: array
            items:
              type: string
              nullable: true
            description: A list of Microsoft Entra tenant IDs in which the client application is registered, or a list with the single value all to match with client apps registered in any tenant. Default is the single value all.
          permissionClassification:
            type: string
            description: The permission classification for the permission being granted, or all to match with any permission classification (including permissions that aren't classified). Default is all.
            nullable: true
          permissions:
            type: array
            items:
              type: string
              nullable: true
            description: The list of id values for the specific permissions to match with, or a list with the single value all to match with any permission. The id of delegated permissions can be found in the oauth2PermissionScopes property of the API's servicePrincipal object. The id of application permissions can be found in the appRoles property of the API's servicePrincipal object. The id of resource-specific application permissions can be found in the resourceSpecificApplicationPermissions property of the API's servicePrincipal object. Default is the single value all.
          permissionType:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.permissionType'
            - type: object
              nullable: true
            description: 'The permission type of the permission being granted. Possible values: application for application permissions (for example app roles), or delegated for delegated permissions. The value delegatedUserConsentable indicates delegated permissions that haven''t been configured by the API publisher to require admin consent—this value may be used in built-in permission grant policies, but can''t be used in custom permission grant policies. Required.'
          resourceApplication:
            type: string
            description: The appId of the resource application (for example the API) for which a permission is being granted, or any to match with any resource application or API. Default is any.
            nullable: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.permissionGrantConditionSet'
    microsoft.graph.policyBase:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.directoryObject'
      - title: policyBase
        required:
        - '@odata.type'
        type: object
        properties:
          description:
            type: string
            description: Description for this policy. Required.
            nullable: true
          displayName:
            type: string
            description: Display name for this policy. Required.
            nullable: true
          '@odata.type':
            type: string
            default: '#microsoft.graph.policyBase'
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.appManagementPolicy': '#/components/schemas/microsoft.graph.appManagementPolicy'
            '#microsoft.graph.authorizationPolicy': '#/components/schemas/microsoft.graph.authorizationPolicy'
            '#microsoft.graph.crossTenantAccessPolicy': '#/components/schemas/microsoft.graph.crossTenantAccessPolicy'
            '#microsoft.graph.identitySecurityDefaultsEnforcementPolicy': '#/components/schemas/microsoft.graph.identitySecurityDefaultsEnforcementPolicy'
            '#microsoft.graph.permissionGrantPolicy': '#/components/schemas/microsoft.graph.permissionGrantPolicy'
            '#microsoft.graph.stsPolicy': '#/components/schemas/microsoft.graph.stsPolicy'
            '#microsoft.graph.activityBasedTimeoutPolicy': '#/components/schemas/microsoft.graph.activityBasedTimeoutPolicy'
            '#microsoft.graph.claimsMappingPolicy': '#/components/schemas/microsoft.graph.claimsMappingPolicy'
            '#microsoft.graph.homeRealmDiscoveryPolicy': '#/components/schemas/microsoft.graph.homeRealmDiscoveryPolicy'
            '#microsoft.graph.tokenIssuancePolicy': '#/components/schemas/microsoft.graph.tokenIssuancePolicy'
            '#microsoft.graph.tokenLifetimePolicy': '#/components/schemas/microsoft.graph.tokenLifetimePolicy'
            '#microsoft.graph.tenantAppManagementPolicy': '#/components/schemas/microsoft.graph.tenantAppManagementPolicy'
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        required:
        - '@odata.type'
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
            nullable: true
          '@odata.type':
            type: string
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.administrativeUnit': '#/components/schemas/microsoft.graph.administrativeUnit'
            '#microsoft.graph.application': '#/components/schemas/microsoft.graph.application'
            '#microsoft.graph.appRoleAssignment': '#/components/schemas/microsoft.graph.appRoleAssignment'
            '#microsoft.graph.certificateAuthorityDetail': '#/components/schemas/microsoft.graph.certificateAuthorityDetail'
            '#microsoft.graph.certificateBasedAuthPki': '#/components/schemas/microsoft.graph.certificateBasedAuthP

# --- truncated at 32 KB (160 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/microsoft-graph/refs/heads/main/openapi/microsoft-graph-policies-permissiongrantpolicy-api-openapi.yml