Microsoft Graph security.triggersRoot API

The security.triggersRoot API from Microsoft Graph — 5 operation(s) for security.triggersroot.

Operations 10

GET /security/triggers Microsoft Graph Get triggers from security #
PATCH /security/triggers Microsoft Graph Update the navigation property triggers in security #
DELETE /security/triggers Microsoft Graph Delete navigation property triggers for security #
GET /security/triggers/retentionEvents Microsoft Graph List retentionEvents #
POST /security/triggers/retentionEvents Microsoft Graph Create retentionEvent #
GET /security/triggers/retentionEvents/{retentionEvent-id} Microsoft Graph Get retentionEvent #
PATCH /security/triggers/retentionEvents/{retentionEvent-id} Microsoft Graph Update the navigation property retentionEvents in security #
DELETE /security/triggers/retentionEvents/{retentionEvent-id} Microsoft Graph Delete retentionEvent #
GET /security/triggers/retentionEvents/{retentionEvent-id}/retentionEventType Microsoft Graph Get retentionEventType from security #
GET /security/triggers/retentionEvents/$count Microsoft Graph Get the number of the resource #

Documentation

📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/admin?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreementacceptance?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamsapp?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/applicationtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodspolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/certificatebasedauthconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/chat?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/communications-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/complianceapioverview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-externalconnection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contract?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/copilot-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/datapolicyoperation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-apps-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-device-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/directory?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domaindnsrecord?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domain?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/drive?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/education-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/employee-experience-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-external?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/filter-query-parameter
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/grouplifecyclepolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsetting?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsettingtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/identitycontainer?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/informationprotection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/invitation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/users?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/oauth2permissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/resourcespecificpermissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/place?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/planner-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/policy-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/print?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/privacy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/report?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/rolemanagement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/scopedrolemembership?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/search-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/serviceprincipal?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/shares?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sharepoint?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/solutions-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/filestorage?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscribedsku?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamwork?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/tenantrelationship?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/auth/auth-concepts
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/workplace?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sitepage?view=graph-rest-1.0

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/microsoft-graph-security-triggersroot-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

microsoft-graph-security-triggersroot-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Microsoft Graph Admin Admin.admin Security.triggers Root API
  description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID.

    This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations,

    site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements,

    SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.'
  version: 1.0.0
  contact:
    name: Microsoft Graph API Support
    url: https://developer.microsoft.com/graph
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph API v1.0 endpoint
tags:
- name: security.triggersRoot
  x-ms-docs-toc-type: page
paths:
  /security/triggers:
    description: Provides operations to manage the triggers property of the microsoft.graph.security entity.
    get:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Get triggers from security
      operationId: security.GetTriggers
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.security.triggersRoot'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Update the navigation property triggers in security
      operationId: security.UpdateTriggers
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.security.triggersRoot'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.security.triggersRoot'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Delete navigation property triggers for security
      operationId: security.DeleteTriggers
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /security/triggers/retentionEvents:
    description: Provides operations to manage the retentionEvents property of the microsoft.graph.security.triggersRoot entity.
    get:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph List retentionEvents
      description: Get a list of the retentionEvent objects and their properties.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/security-retentionevent-list?view=graph-rest-1.0
      operationId: security.triggers.ListRetentionEvents
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.security.retentionEventCollectionResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Create retentionEvent
      description: Create a new retentionEvent object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/security-retentionevent-post?view=graph-rest-1.0
      operationId: security.triggers.CreateRetentionEvents
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /security/triggers/retentionEvents/{retentionEvent-id}:
    description: Provides operations to manage the retentionEvents property of the microsoft.graph.security.triggersRoot entity.
    parameters:
    - name: retentionEvent-id
      in: path
      description: The unique identifier of retentionEvent
      required: true
      schema:
        type: string
      x-ms-docs-key-type: retentionEvent
    get:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Get retentionEvent
      description: Read the properties and relationships of a retentionEvent object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/security-retentionevent-get?view=graph-rest-1.0
      operationId: security.triggers.GetRetentionEvents
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Update the navigation property retentionEvents in security
      operationId: security.triggers.UpdateRetentionEvents
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Delete retentionEvent
      description: Delete a retentionEvent object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/security-retentionevent-delete?view=graph-rest-1.0
      operationId: security.triggers.DeleteRetentionEvents
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /security/triggers/retentionEvents/{retentionEvent-id}/retentionEventType:
    description: Provides operations to manage the retentionEventType property of the microsoft.graph.security.retentionEvent entity.
    parameters:
    - name: retentionEvent-id
      in: path
      description: The unique identifier of retentionEvent
      required: true
      schema:
        type: string
      x-ms-docs-key-type: retentionEvent
    get:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Get retentionEventType from security
      description: Specifies the event that will start the retention period for labels that use this event type when an event is created.
      operationId: security.triggers.retentionEvents.GetRetentionEventType
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.security.retentionEventType'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /security/triggers/retentionEvents/$count:
    description: Provides operations to count the resources in the collection.
    get:
      tags:
      - security.triggersRoot
      summary: Microsoft Graph Get the number of the resource
      operationId: security.triggers.retentionEvents.GetCount-84a4
      parameters:
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
components:
  schemas:
    ODataCountResponse:
      type: integer
      format: int32
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type: string
          nullable: true
    microsoft.graph.security.eventPropagationResult:
      title: eventPropagationResult
      required:
      - '@odata.type'
      type: object
      properties:
        location:
          type: string
          description: The name of the specific location in the workload associated with the event.
          nullable: true
        serviceName:
          type: string
          description: The name of the workload associated with the event.
          nullable: true
        status:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.security.eventPropagationStatus'
          - type: object
            nullable: true
          description: 'Indicates the status of the event creation request. The possible values are: none, inProcessing, failed, success, unknownFutureValue.'
        statusInformation:
          type: string
          description: Additional information about the status of the event creation request.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.identity:
      title: identity
      required:
      - '@odata.type'
      type: object
      properties:
        displayName:
          type: string
          description: The display name of the identity.For drive items, the display name might not always be available or up to date. For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta.
          nullable: true
        id:
          type: string
          description: Unique identifier for the identity or actor. For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review.
          nullable: true
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.azureCommunicationServicesUserIdentity': '#/components/schemas/microsoft.graph.azureCommunicationServicesUserIdentity'
          '#microsoft.graph.communicationsApplicationIdentity': '#/components/schemas/microsoft.graph.communicationsApplicationIdentity'
          '#microsoft.graph.communicationsApplicationInstanceIdentity': '#/components/schemas/microsoft.graph.communicationsApplicationInstanceIdentity'
          '#microsoft.graph.communicationsEncryptedIdentity': '#/components/schemas/microsoft.graph.communicationsEncryptedIdentity'
          '#microsoft.graph.communicationsGuestIdentity': '#/components/schemas/microsoft.graph.communicationsGuestIdentity'
          '#microsoft.graph.communicationsPhoneIdentity': '#/components/schemas/microsoft.graph.communicationsPhoneIdentity'
          '#microsoft.graph.communicationsUserIdentity': '#/components/schemas/microsoft.graph.communicationsUserIdentity'
          '#microsoft.graph.emailIdentity': '#/components/schemas/microsoft.graph.emailIdentity'
          '#microsoft.graph.initiator': '#/components/schemas/microsoft.graph.initiator'
          '#microsoft.graph.provisionedIdentity': '#/components/schemas/microsoft.graph.provisionedIdentity'
          '#microsoft.graph.provisioningServicePrincipal': '#/components/schemas/microsoft.graph.provisioningServicePrincipal'
          '#microsoft.graph.provisioningSystem': '#/components/schemas/microsoft.graph.provisioningSystem'
          '#microsoft.graph.servicePrincipalIdentity': '#/components/schemas/microsoft.graph.servicePrincipalIdentity'
          '#microsoft.graph.sharePointIdentity': '#/components/schemas/microsoft.graph.sharePointIdentity'
          '#microsoft.graph.teamworkApplicationIdentity': '#/components/schemas/microsoft.graph.teamworkApplicationIdentity'
          '#microsoft.graph.teamworkConversationIdentity': '#/components/schemas/microsoft.graph.teamworkConversationIdentity'
          '#microsoft.graph.teamworkTagIdentity': '#/components/schemas/microsoft.graph.teamworkTagIdentity'
          '#microsoft.graph.teamworkUserIdentity': '#/components/schemas/microsoft.graph.teamworkUserIdentity'
          '#microsoft.graph.userIdentity': '#/components/schemas/microsoft.graph.userIdentity'
          '#microsoft.graph.callRecords.userIdentity': '#/components/schemas/microsoft.graph.callRecords.userIdentity'
    microsoft.graph.security.retentionEventCollectionResponse:
      title: Collection of retentionEvent
      type: object
      allOf:
      - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
      - type: object
        properties:
          value:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
    microsoft.graph.security.eventPropagationStatus:
      title: eventPropagationStatus
      enum:
      - none
      - inProcessing
      - failed
      - success
      - unknownFutureValue
      type: string
    microsoft.graph.security.retentionEventStatus:
      title: retentionEventStatus
      required:
      - '@odata.type'
      type: object
      properties:
        error:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.publicError'
          - type: object
            nullable: true
          description: The error if the status isn't successful.
        status:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.security.eventStatusType'
          - type: object
            nullable: true
          description: 'The status of the distribution. The possible values are: pending, error, success, notAvaliable.'
        '@odata.type':
          type: string
    microsoft.graph.ODataErrors.InnerError:
      title: InnerError
      required:
      - '@odata.type'
      type: object
      properties:
        request-id:
          type: string
          description: Request Id as tracked internally by the service
          nullable: true
        client-request-id:
          type: string
          description: Client request Id as sent by the client application.
          nullable: true
        date:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date when the error occured.
          format: date-time
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.security.eventStatusType:
      title: eventStatusType
      enum:
      - pending
      - error
      - success
      - notAvaliable
      - unknownFutureValue
      type: string
    microsoft.graph.security.eventQuery:
      title: eventQuery
      required:
      - '@odata.type'
      type: object
      properties:
        query:
          type: string
          description: Represents unique identification for the  query. 'Asset ID' for SharePoint Online and OneDrive for Business, 'keywords' for Exchange Online.
        queryType:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.security.queryType'
          - type: object
            nullable: true
          description: 'Represents the type of query associated with an event. ''files'' for SPO and ODB and ''messages'' for EXO.The possible values are: files, messages, unknownFutureValue.'
        '@odata.type':
          type: string
    microsoft.graph.publicErrorDetail:
      title: publicErrorDetail
      required:
      - '@odata.type'
      type: object
      properties:
        code:
          type: string
          description: The error code.
          nullable: true
        message:
          type: string
          description: The error message.
          nullable: true
        target:
          type: string
          description: The target of the error.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.publicInnerError:
      title: publicInnerError
      required:
      - '@odata.type'
      type: object
      properties:
        code:
          type: string
          description: The error code.
          nullable: true
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.publicErrorDetail'
          description: A collection of error details.
        message:
          type: string
          description: The error message.
          nullable: true
        target:
          type: string
          description: The target of the error.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.security.retentionEventType:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: retentionEventType
        required:
        - '@odata.type'
        type: object
        properties:
          createdBy:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.identitySet'
            - type: object
              nullable: true
            description: The user who created the retentionEventType.
          createdDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The date time when the retentionEventType was created.
            format: date-time
            nullable: true
          description:
            type: string
            description: Optional information about the event type.
            nullable: true
          displayName:
            type: string
            description: Name of the event type.
            nullable: true
          lastModifiedBy:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.identitySet'
            - type: object
              nullable: true
            description: The user who last modified the retentionEventType.
          lastModifiedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The latest date time when the retentionEventType was modified.
            format: date-time
            nullable: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.security.retentionEventType'
    microsoft.graph.security.queryType:
      title: queryType
      enum:
      - files
      - messages
      - unknownFutureValue
      type: string
    microsoft.graph.security.triggersRoot:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: triggersRoot
        required:
        - '@odata.type'
        type: object
        properties:
          retentionEvents:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.security.retentionEvent'
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.security.triggersRoot'
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type: string
          nullable: true
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
    microsoft.graph.security.retentionEvent:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: retentionEvent
        required:
        - '@odata.type'
        type: object
        properties:
          createdBy:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.identitySet'
            - type: object
              nullable: true
            description: The user who created the retentionEvent.
          createdDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The date time when the retentionEvent was created.
            format: date-time
            nullable: true
          description:
            type: string
            description: Optional information about the event.
            nullable: true
          displayName:
            type: string
            description: Name of the event.
            nullable: true
          eventPropagationResults:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.security.eventPropagationResult'
            description: Represents the success status of a created event and additional information.
          eventQueries:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.security.eventQuery'
            description: Represents the workload (SharePoint Online, OneDrive for Business, Exchange Online) and identification information associated with a retention event.
          eventStatus:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.security.retentionEventStatus'
            - type: object
              nullable: true
            description: Status of event propogation to the scoped locations after the event has been created.
          eventTriggerDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: Optional time when the event should be triggered.
            format: date-time
            nullable: true
          lastModifiedBy:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.identitySet'
            - type: object
              nullable: true
            description: The user who last modified the retentionEvent.
          lastModifiedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: The latest date time when the retentionEvent was modified.
            format: date-time
            nullable: true
          lastStatusUpdateDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: Last time the status of the event was updated.
            format: date-time
            nullable: true
          retentionEventType:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.security.retentionEventType'
            - type: object
              nullable: true
            description: Specifies the event that will start the retention period for labels that use this event type when an event is created.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.security.retentionEvent'
    BaseCollectionPaginationCountResponse:
      title: Base collection pagination and count responses
      type: object
      properties:
        '@odata.count':
          type: integer
          format: int64
          nullable: true
        '@odata.nextLink':
          type: string
          nullable: true
    microsoft.graph.ODataErrors.ODataError:
      required:
      - error
      type: object
      properties:
        error:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
    microsoft.graph.identitySet:
      title: identitySet
      required:
      - '@odata.type'
      type: object
      properties:
        application:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.identity'
          - type: object
            nullable: true
          description: Optional. The application associated with this action.
        device:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.identity'
          - type: object
            nullable: true
          description: Optional. The device associated with this action.
        user:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.identity'
          - type: object
            nullable: true
          description: Optional. The user associated with this action.
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.aiInteractionMentionedIdentitySet': '#/components/schemas/microsoft.graph.aiInteractionMentionedIdentitySet'
          '#microsoft.graph.chatMessageFromIdentitySet': '#/components/schemas/microsoft.graph.chatMessageFromIdentitySet'
          '#microsoft.graph.chatMessageMentionedIdentitySet': '#/components/schemas/microsoft.graph.chatMessageMentionedIdentitySet'
          '#microsoft.graph.chatMessageReactionIdentitySet': '#/components/schemas/microsoft.graph.chatMessageReactionIdentitySet'
          '#microsoft.graph.communicationsIdentitySet': '#/components/schemas/microsoft.graph.communicationsIdentitySet'
          '#microsoft.graph.engagementIdentitySet': '#/components/schemas/microsoft.graph.engagementIdentitySet'
          '#microsoft.graph.sharePointIdentitySet': '#/components/schemas/microsoft.graph.sharePointIdentitySet'
    microsoft.graph.publicError:
      title: publicError
      required:
      - '@odata.type'
      type: object
      properties:
        code:
          type: string
          description: Represents the error code.
          nullable: true
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.publicErrorDetail'
          description: Details of the error.
        innerError:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.publicInnerError'
          - type: object
            nullable: true
          description: Details of the inner error.
        message:
          type: string
          description: A non-localized message for the developer.
          nullable: true
        target:
          type: string
          description: The target of the error.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.entity:
      title: entity
      required:
      - '@odata.type'
      type: object
      properties:
        id:
          type: string
          description: The unique identifier for an entity. Read-only.
        '@odata.type':
          type: string
      discriminator:
        propertyName: '@odata.type'
        mapping:
          '#microsoft.graph.accessPackage': '#/components/schemas/microsoft.graph.accessPackage'
          '#microsoft.graph.accessPackageAssignment': '#/components/schemas/microsoft.graph.accessPackageAssignment'
          '#microsoft.graph.accessPackageAssignmentPolicy': '#/components/schemas/microsoft.graph.accessPackageAssignmentPolicy'
          '#microsoft.graph.accessPackageAssignmentRequest': '#/components/schemas/microsoft.graph.accessPackageAssignmentRequest'
          '#microsoft.graph.accessPackageCatalog': '#/components/schemas/microsoft.graph.accessPackageCatalog'
          '#microsoft.graph.accessPackageQuestion': '#/components/schemas/microsoft.graph.accessPackageQuestion'
          '#microsoft.graph.accessPackageMultipleChoiceQuestion': '#/components/schemas/microsoft.graph.accessPackageMultipleChoiceQuestion'
          '#microsoft.graph.accessPackageTextInputQuestion': '#/components/schemas/microsoft.graph.accessPackageTextInputQuestion'
          '#microsoft.graph.accessPackageResource': '#/components/schemas/microsoft.graph.accessPackageResource'
          '#microsoft.graph.accessPackageResourceEnvironment': '#/components/schemas/microsoft.graph.accessPackageResourceEnvironment'
          '#microsoft.graph.accessPackageResourceRequest': '#/components/schemas/microsoft.graph.accessPackageResourceRequest'
          '#microsoft.graph.accessPackageResourceRole': '#/components/schemas/microsoft.graph.accessPackageResourceRole'
          '#microsoft.graph.accessPackageResourceRoleScope': '#/components/schemas/microsoft.graph.accessPackageReso

# --- truncated at 32 KB (152 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/microsoft-graph/refs/heads/main/openapi/microsoft-graph-security-triggersroot-api-openapi.yml