Microsoft Graph policies.policyRoot API

The policies.policyRoot API from Microsoft Graph — 1 operation(s) for policies.policyroot.

Operations 2

GET /policies Microsoft Graph Get policies #
PATCH /policies Microsoft Graph Update policies #

Documentation

📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/admin?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreementacceptance?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamsapp?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/applicationtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodspolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/certificatebasedauthconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/chat?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/communications-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/complianceapioverview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-externalconnection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contract?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/copilot-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/datapolicyoperation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-apps-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-device-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/directory?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domaindnsrecord?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domain?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/drive?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/education-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/employee-experience-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-external?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/filter-query-parameter
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/grouplifecyclepolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsetting?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsettingtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/identitycontainer?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/informationprotection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/invitation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/users?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/oauth2permissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/resourcespecificpermissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/place?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/planner-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/policy-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/print?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/privacy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/report?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/rolemanagement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/scopedrolemembership?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/search-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/serviceprincipal?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/shares?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sharepoint?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/solutions-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/filestorage?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscribedsku?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamwork?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/tenantrelationship?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/auth/auth-concepts
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/workplace?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sitepage?view=graph-rest-1.0

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/microsoft-graph-policies-policyroot-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

microsoft-graph-policies-policyroot-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Microsoft Graph Admin Admin.admin Policies.policy Root API
  description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID.

    This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations,

    site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements,

    SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.'
  version: 1.0.0
  contact:
    name: Microsoft Graph API Support
    url: https://developer.microsoft.com/graph
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph API v1.0 endpoint
tags:
- name: policies.policyRoot
  x-ms-docs-toc-type: page
paths:
  /policies:
    description: Provides operations to manage the policyRoot singleton.
    get:
      tags:
      - policies.policyRoot
      summary: Microsoft Graph Get policies
      operationId: policies.policyRoot.GetPolicyRoot
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved entity
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.policyRoot'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - policies.policyRoot
      summary: Microsoft Graph Update policies
      operationId: policies.policyRoot.UpdatePolicyRoot
      requestBody:
        description: New property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.policyRoot'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.policyRoot'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
components:
  schemas:
    microsoft.graph.conditionalAccessLocations:
      title: conditionalAccessLocations
      required:
      - '@odata.type'
      type: object
      properties:
        excludeLocations:
          type: array
          items:
            type: string
          description: Location IDs excluded from scope of policy.
        includeLocations:
          type: array
          items:
            type: string
          description: Location IDs in scope of policy unless explicitly excluded, All, or AllTrusted.
        '@odata.type':
          type: string
    microsoft.graph.authenticationFlowsPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: authenticationFlowsPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          description:
            type: string
            description: Inherited property. A description of the policy. Optional. Read-only.
            nullable: true
          displayName:
            type: string
            description: Inherited property. The human-readable name of the policy. Optional. Read-only.
            nullable: true
          selfServiceSignUp:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.selfServiceSignUpAuthenticationFlowConfiguration'
            - type: object
              nullable: true
            description: Contains selfServiceSignUpAuthenticationFlowConfiguration settings that convey whether self-service sign-up is enabled or disabled. Optional. Read-only.
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.authenticationFlowsPolicy'
    microsoft.graph.conditionalAccessGuestsOrExternalUsers:
      title: conditionalAccessGuestsOrExternalUsers
      required:
      - '@odata.type'
      type: object
      properties:
        externalTenants:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenants'
          - type: object
            nullable: true
          description: The tenant IDs of the selected types of external users. Either all B2B tenant or a collection of tenant IDs. External tenants can be specified only when the property guestOrExternalUserTypes isn't null or an empty String.
        guestOrExternalUserTypes:
          $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestOrExternalUserTypes'
        '@odata.type':
          type: string
    microsoft.graph.identity:
      title: identity
      required:
      - '@odata.type'
      type: object
      properties:
        displayName:
          type: string
          description: The display name of the identity.For drive items, the display name might not always be available or up to date. For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta.
          nullable: true
        id:
          type: string
          description: Unique identifier for the identity or actor. For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review.
          nullable: true
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.azureCommunicationServicesUserIdentity': '#/components/schemas/microsoft.graph.azureCommunicationServicesUserIdentity'
          '#microsoft.graph.communicationsApplicationIdentity': '#/components/schemas/microsoft.graph.communicationsApplicationIdentity'
          '#microsoft.graph.communicationsApplicationInstanceIdentity': '#/components/schemas/microsoft.graph.communicationsApplicationInstanceIdentity'
          '#microsoft.graph.communicationsEncryptedIdentity': '#/components/schemas/microsoft.graph.communicationsEncryptedIdentity'
          '#microsoft.graph.communicationsGuestIdentity': '#/components/schemas/microsoft.graph.communicationsGuestIdentity'
          '#microsoft.graph.communicationsPhoneIdentity': '#/components/schemas/microsoft.graph.communicationsPhoneIdentity'
          '#microsoft.graph.communicationsUserIdentity': '#/components/schemas/microsoft.graph.communicationsUserIdentity'
          '#microsoft.graph.emailIdentity': '#/components/schemas/microsoft.graph.emailIdentity'
          '#microsoft.graph.initiator': '#/components/schemas/microsoft.graph.initiator'
          '#microsoft.graph.provisionedIdentity': '#/components/schemas/microsoft.graph.provisionedIdentity'
          '#microsoft.graph.provisioningServicePrincipal': '#/components/schemas/microsoft.graph.provisioningServicePrincipal'
          '#microsoft.graph.provisioningSystem': '#/components/schemas/microsoft.graph.provisioningSystem'
          '#microsoft.graph.servicePrincipalIdentity': '#/components/schemas/microsoft.graph.servicePrincipalIdentity'
          '#microsoft.graph.sharePointIdentity': '#/components/schemas/microsoft.graph.sharePointIdentity'
          '#microsoft.graph.teamworkApplicationIdentity': '#/components/schemas/microsoft.graph.teamworkApplicationIdentity'
          '#microsoft.graph.teamworkConversationIdentity': '#/components/schemas/microsoft.graph.teamworkConversationIdentity'
          '#microsoft.graph.teamworkTagIdentity': '#/components/schemas/microsoft.graph.teamworkTagIdentity'
          '#microsoft.graph.teamworkUserIdentity': '#/components/schemas/microsoft.graph.teamworkUserIdentity'
          '#microsoft.graph.userIdentity': '#/components/schemas/microsoft.graph.userIdentity'
          '#microsoft.graph.callRecords.userIdentity': '#/components/schemas/microsoft.graph.callRecords.userIdentity'
    microsoft.graph.devicesFilter:
      title: devicesFilter
      required:
      - '@odata.type'
      type: object
      properties:
        mode:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.crossTenantAccessPolicyTargetConfigurationAccessType'
          - type: object
            nullable: true
          description: 'Determines whether devices that satisfy the rule should be allowed or blocked. The possible values are: allowed, blocked, unknownFutureValue.'
        rule:
          type: string
          description: Defines the rule to filter the devices. For example, device.deviceAttribute2 -eq 'PrivilegedAccessWorkstation'.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.appManagementServicePrincipalConfiguration:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.appManagementConfiguration'
      - title: appManagementServicePrincipalConfiguration
        required:
        - '@odata.type'
        type: object
        properties:
          '@odata.type':
            type: string
            default: '#microsoft.graph.appManagementServicePrincipalConfiguration'
      x-ms-discriminator-value: '#microsoft.graph.appManagementServicePrincipalConfiguration'
    microsoft.graph.authenticationStrengthPolicyType:
      title: authenticationStrengthPolicyType
      enum:
      - builtIn
      - custom
      - unknownFutureValue
      type: string
    microsoft.graph.conditionalAccessAuthenticationFlows:
      title: conditionalAccessAuthenticationFlows
      required:
      - '@odata.type'
      type: object
      properties:
        transferMethods:
          $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods'
        '@odata.type':
          type: string
    microsoft.graph.authenticationMethodsRegistrationCampaign:
      title: authenticationMethodsRegistrationCampaign
      required:
      - '@odata.type'
      type: object
      properties:
        excludeTargets:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.excludeTarget'
          description: Users and groups of users that are excluded from being prompted to set up the authentication method.
        includeTargets:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.authenticationMethodsRegistrationCampaignIncludeTarget'
          description: Users and groups of users that are prompted to set up the authentication method.
        snoozeDurationInDays:
          maximum: 2147483647
          minimum: -2147483648
          type: number
          description: 'Specifies the number of days that the user sees a prompt again if they select ''Not now'' and snoozes the prompt. Minimum: 0 days. Maximum: 14 days. If the value is ''0'', the user is prompted during every MFA attempt.'
          format: int32
        state:
          $ref: '#/components/schemas/microsoft.graph.advancedConfigState'
        '@odata.type':
          type: string
    microsoft.graph.ODataErrors.InnerError:
      title: InnerError
      required:
      - '@odata.type'
      type: object
      properties:
        request-id:
          type: string
          description: Request Id as tracked internally by the service
          nullable: true
        client-request-id:
          type: string
          description: Client request Id as sent by the client application.
          nullable: true
        date:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date when the error occured.
          format: date-time
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.authenticationMethodsPolicyMigrationState:
      title: authenticationMethodsPolicyMigrationState
      enum:
      - preMigration
      - migrationInProgress
      - migrationComplete
      - unknownFutureValue
      type: string
    microsoft.graph.unifiedRoleManagementPolicyRuleTargetOperations:
      title: unifiedRoleManagementPolicyRuleTargetOperations
      enum:
      - all
      - activate
      - deactivate
      - assign
      - update
      - remove
      - extend
      - renew
      - unknownFutureValue
      type: string
    microsoft.graph.accessReviewReviewerScope:
      title: accessReviewReviewerScope
      required:
      - '@odata.type'
      type: object
      properties:
        query:
          type: string
          description: The query specifying who will be the reviewer.
          nullable: true
        queryRoot:
          type: string
          description: 'In the scenario where reviewers need to be specified dynamically, this property is used to indicate the relative source of the query. This property is only required if a relative query, for example, ./manager, is specified. Possible value: decisions.'
          nullable: true
        queryType:
          type: string
          description: The type of query. Examples include MicrosoftGraph and ARM.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.signInFrequencyInterval:
      title: signInFrequencyInterval
      enum:
      - timeBased
      - everyTime
      - unknownFutureValue
      type: string
    microsoft.graph.conditionalAccessSessionControls:
      title: conditionalAccessSessionControls
      required:
      - '@odata.type'
      type: object
      properties:
        applicationEnforcedRestrictions:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl'
          - type: object
            nullable: true
          description: Session control to enforce application restrictions. Only Exchange Online and Sharepoint Online support this session control.
        cloudAppSecurity:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl'
          - type: object
            nullable: true
          description: Session control to apply cloud app security.
        disableResilienceDefaults:
          type: boolean
          description: Session control that determines whether it is acceptable for Microsoft Entra ID to extend existing sessions based on information collected prior to an outage or not.
          nullable: true
        persistentBrowser:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionControl'
          - type: object
            nullable: true
          description: Session control to define whether to persist cookies or not. All apps should be selected for this session control to work correctly.
        secureSignInSession:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.secureSignInSessionControl'
          - type: object
            nullable: true
        signInFrequency:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.signInFrequencySessionControl'
          - type: object
            nullable: true
          description: Session control to enforce signin frequency.
        '@odata.type':
          type: string
    microsoft.graph.persistentBrowserSessionMode:
      title: persistentBrowserSessionMode
      enum:
      - always
      - never
      type: string
    microsoft.graph.conditionalAccessPolicyState:
      title: conditionalAccessPolicyState
      enum:
      - enabled
      - disabled
      - enabledForReportingButNotEnforced
      type: string
    microsoft.graph.appManagementPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.policyBase'
      - title: appManagementPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          isEnabled:
            type: boolean
            description: Denotes whether the policy is enabled.
          restrictions:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.customAppManagementConfiguration'
            - type: object
              nullable: true
            description: Restrictions that apply to an application or service principal object.
          appliesTo:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.directoryObject'
            description: Collection of applications and service principals to which the policy is applied.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
            default: '#microsoft.graph.appManagementPolicy'
      x-ms-discriminator-value: '#microsoft.graph.appManagementPolicy'
    microsoft.graph.crossTenantAccessPolicyB2BSetting:
      title: crossTenantAccessPolicyB2BSetting
      required:
      - '@odata.type'
      type: object
      properties:
        applications:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.crossTenantAccessPolicyTargetConfiguration'
          - type: object
            nullable: true
          description: The list of applications targeted with your cross-tenant access policy.
        usersAndGroups:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.crossTenantAccessPolicyTargetConfiguration'
          - type: object
            nullable: true
          description: The list of users and groups targeted with your cross-tenant access policy.
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.crossTenantAccessPolicyTenantRestrictions': '#/components/schemas/microsoft.graph.crossTenantAccessPolicyTenantRestrictions'
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        required:
        - '@odata.type'
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
            nullable: true
          '@odata.type':
            type: string
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.administrativeUnit': '#/components/schemas/microsoft.graph.administrativeUnit'
            '#microsoft.graph.application': '#/components/schemas/microsoft.graph.application'
            '#microsoft.graph.appRoleAssignment': '#/components/schemas/microsoft.graph.appRoleAssignment'
            '#microsoft.graph.certificateAuthorityDetail': '#/components/schemas/microsoft.graph.certificateAuthorityDetail'
            '#microsoft.graph.certificateBasedAuthPki': '#/components/schemas/microsoft.graph.certificateBasedAuthPki'
            '#microsoft.graph.contract': '#/components/schemas/microsoft.graph.contract'
            '#microsoft.graph.device': '#/components/schemas/microsoft.graph.device'
            '#microsoft.graph.directoryObjectPartnerReference': '#/components/schemas/microsoft.graph.directoryObjectPartnerReference'
            '#microsoft.graph.directoryRole': '#/components/schemas/microsoft.graph.directoryRole'
            '#microsoft.graph.directoryRoleTemplate': '#/components/schemas/microsoft.graph.directoryRoleTemplate'
            '#microsoft.graph.endpoint': '#/components/schemas/microsoft.graph.endpoint'
            '#microsoft.graph.extensionProperty': '#/components/schemas/microsoft.graph.extensionProperty'
            '#microsoft.graph.group': '#/components/schemas/microsoft.graph.group'
            '#microsoft.graph.groupSettingTemplate': '#/components/schemas/microsoft.graph.groupSettingTemplate'
            '#microsoft.graph.multiTenantOrganizationMember': '#/components/schemas/microsoft.graph.multiTenantOrganizationMember'
            '#microsoft.graph.organization': '#/components/schemas/microsoft.graph.organization'
            '#microsoft.graph.orgContact': '#/components/schemas/microsoft.graph.orgContact'
            '#microsoft.graph.policyBase': '#/components/schemas/microsoft.graph.policyBase'
            '#microsoft.graph.appManagementPolicy': '#/components/schemas/microsoft.graph.appManagementPolicy'
            '#microsoft.graph.authorizationPolicy': '#/components/schemas/microsoft.graph.authorizationPolicy'
            '#microsoft.graph.crossTenantAccessPolicy': '#/components/schemas/microsoft.graph.crossTenantAccessPolicy'
            '#microsoft.graph.identitySecurityDefaultsEnforcementPolicy': '#/components/schemas/microsoft.graph.identitySecurityDefaultsEnforcementPolicy'
            '#microsoft.graph.permissionGrantPolicy': '#/components/schemas/microsoft.graph.permissionGrantPolicy'
            '#microsoft.graph.stsPolicy': '#/components/schemas/microsoft.graph.stsPolicy'
            '#microsoft.graph.activityBasedTimeoutPolicy': '#/components/schemas/microsoft.graph.activityBasedTimeoutPolicy'
            '#microsoft.graph.claimsMappingPolicy': '#/components/schemas/microsoft.graph.claimsMappingPolicy'
            '#microsoft.graph.homeRealmDiscoveryPolicy': '#/components/schemas/microsoft.graph.homeRealmDiscoveryPolicy'
            '#microsoft.graph.tokenIssuancePolicy': '#/components/schemas/microsoft.graph.tokenIssuancePolicy'
            '#microsoft.graph.tokenLifetimePolicy': '#/components/schemas/microsoft.graph.tokenLifetimePolicy'
            '#microsoft.graph.tenantAppManagementPolicy': '#/components/schemas/microsoft.graph.tenantAppManagementPolicy'
            '#microsoft.graph.resourceSpecificPermissionGrant': '#/components/schemas/microsoft.graph.resourceSpecificPermissionGrant'
            '#microsoft.graph.servicePrincipal': '#/components/schemas/microsoft.graph.servicePrincipal'
            '#microsoft.graph.user': '#/components/schemas/microsoft.graph.user'
    microsoft.graph.appKeyCredentialRestrictionType:
      title: appKeyCredentialRestrictionType
      enum:
      - asymmetricKeyLifetime
      - unknownFutureValue
      type: string
    microsoft.graph.tokenIssuancePolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.stsPolicy'
      - title: tokenIssuancePolicy
        required:
        - '@odata.type'
        type: object
        properties:
          '@odata.type':
            type: string
            default: '#microsoft.graph.tokenIssuancePolicy'
      x-ms-discriminator-value: '#microsoft.graph.tokenIssuancePolicy'
    microsoft.graph.conditionalAccessFilter:
      title: conditionalAccessFilter
      required:
      - '@odata.type'
      type: object
      properties:
        mode:
          $ref: '#/components/schemas/microsoft.graph.filterMode'
        rule:
          type: string
          description: Rule syntax is similar to that used for membership rules for groups in Microsoft Entra ID. For details, see rules with multiple expressions
        '@odata.type':
          type: string
    microsoft.graph.featureRolloutPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: featureRolloutPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          description:
            type: string
            description: A description for this feature rollout policy.
            nullable: true
          displayName:
            type: string
            description: The display name for this  feature rollout policy.
          feature:
            $ref: '#/components/schemas/microsoft.graph.stagedFeatureName'
          isAppliedToOrganization:
            type: boolean
            description: Indicates whether this feature rollout policy should be applied to the entire organization.
          isEnabled:
            type: boolean
            description: Indicates whether the feature rollout is enabled.
          appliesTo:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.directoryObject'
            description: Nullable. Specifies a list of directoryObject resources that feature is enabled for.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.featureRolloutPolicy'
    microsoft.graph.tenantAppManagementPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.policyBase'
      - title: tenantAppManagementPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          applicationRestrictions:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.appManagementApplicationConfiguration'
            - type: object
              nullable: true
            description: Restrictions that apply as default to all application objects in the tenant.
          isEnabled:
            type: boolean
            description: Denotes whether the policy is enabled. Default value is false.
          servicePrincipalRestrictions:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.appManagementServicePrincipalConfiguration'
            - type: object
              nullable: true
            description: Restrictions that apply as default to all service principal objects in the tenant.
          '@odata.type':
            type: string
            default: '#microsoft.graph.tenantAppManagementPolicy'
      x-ms-discriminator-value: '#microsoft.graph.tenantAppManagementPolicy'
    microsoft.graph.authenticationMethodState:
      title: authenticationMethodState
      enum:
      - enabled
      - disabled
      type: string
    microsoft.graph.authenticationStrengthPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: authenticationStrengthPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          allowedCombinations:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes'
            description: A collection of authentication method modes that are required be used to satify this authentication strength.
          createdDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The datetime when this policy was created.
            format: date-time
          description:
            type: string
            description: The human-readable description of this policy.
            nullable: true
          displayName:
            type: string
            description: The human-readable display name of this policy. Supports $filter (eq, ne, not , and in).
          modifiedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The datetime when this policy was last modified.
            format: date-time
          policyType:
            $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyType'
          requirementsSatisfied:
            $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRequirements'
          combinationConfigurations:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration'
            description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.authenticationStrengthPolicy'
    microsoft.graph.authenticationMethodConfiguration:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: authenticationMethodConfiguration
        required:
        - '@odata.type'
        type: object
        properties:
          excludeTargets:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.excludeTarget'
            description: Groups of users that are excluded from a policy.
          state:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.authenticationMethodState'
            - type: object
              nullable: true
            description: 'The state of the policy. The possible values are: enabled, disabled.'
          '@odata.type':
            type: string
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.emailAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.emailAuthenticationMethodConfiguration'
            '#microsoft.graph.fido2AuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.fido2AuthenticationMethodConfiguration'
            '#microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration'
            '#microsoft.graph.smsAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.smsAuthenticationMethodConfiguration'
            '#microsoft.graph.softwareOathAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.softwareOathAuthenticationMethodConfiguration'
            '#microsoft.graph.temporaryAccessPassAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.temporaryAccessPassAuthenticationMethodConfiguration'
            '#microsoft.graph.voiceAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.voiceAuthenticationMethodConfiguration'
            '#microsoft.graph.x509CertificateAuthenticationMethodConfiguration': '#/components/schemas/microsoft.graph.x509CertificateAuthenticationMethodConfiguration'
    microsoft.graph.riskLevel:
      title: riskLevel
      enum:
      - low
      - medium
      - high
      - hidden
      - none
      - unknownFutureValue
      type: string
    microsoft.graph.advancedConfigState:
      title: advancedConfigState
      enum:
      - default
      - enabled
      - disabled
      - unknownFutureValue
      type: string
    microsoft.graph.appManagementConfiguration:
      title: appManagementConfiguration
      required:
      - '@odata.type'
      type: object
      properties:
        keyCredentials:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.keyCredentialConfiguration'
          description: Collection of keyCredential restrictions settings to be applied to an application or service principal.
        passwordCredentials:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.passwordCredentialConfiguration'
          description: Collection of password restrictions settings to be applied to an application or service principal.
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.appManagementApplicationConfiguration': '#/components/schemas/microsoft.graph.appManagementApplicationConfiguration'
          '#microsoft.graph.appManagementServicePrincipalConfiguration': '#/components/schemas/microsoft.graph.appManagementServicePrincipalConfiguration'
          '#microsoft.graph.customAppManagementConfiguration': '#/components/schemas/microsoft.graph.customAppManagementConfiguration'
    microsoft.graph.unifiedRoleManagementPolicyRule:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: unifiedRoleManagementPolicyRule
        required:
        - '@odata.type'
        type: object
        properties:
          target:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementP

# --- truncated at 32 KB (245 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/microsoft-graph/refs/heads/main/openapi/microsoft-graph-policies-policyroot-api-openapi.yml