Microsoft Graph servicePrincipals.servicePrincipal.Actions API

The servicePrincipals.servicePrincipal.Actions API from Microsoft Graph — 13 operation(s) for serviceprincipals.serviceprincipal.actions.

Operations 13

POST /servicePrincipals/{servicePrincipal-id}/addKey Microsoft Graph Invoke action addKey #
POST /servicePrincipals/{servicePrincipal-id}/addPassword Microsoft Graph Invoke action addPassword #
POST /servicePrincipals/{servicePrincipal-id}/addTokenSigningCertificate Microsoft Graph Invoke action addTokenSigningCertificate #
POST /servicePrincipals/{servicePrincipal-id}/checkMemberGroups Microsoft Graph Invoke action checkMemberGroups #
POST /servicePrincipals/{servicePrincipal-id}/checkMemberObjects Microsoft Graph Invoke action checkMemberObjects #
POST /servicePrincipals/{servicePrincipal-id}/getMemberGroups Microsoft Graph Invoke action getMemberGroups #
POST /servicePrincipals/{servicePrincipal-id}/getMemberObjects Microsoft Graph Invoke action getMemberObjects #
POST /servicePrincipals/{servicePrincipal-id}/removeKey Microsoft Graph Invoke action removeKey #
POST /servicePrincipals/{servicePrincipal-id}/removePassword Microsoft Graph Invoke action removePassword #
POST /servicePrincipals/{servicePrincipal-id}/restore Microsoft Graph Invoke action restore #
POST /servicePrincipals/getAvailableExtensionProperties Microsoft Graph Invoke action getAvailableExtensionProperties #
POST /servicePrincipals/getByIds Microsoft Graph Invoke action getByIds #
POST /servicePrincipals/validateProperties Microsoft Graph Invoke action validateProperties #

Documentation

📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/admin?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreementacceptance?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamsapp?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/applicationtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodspolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/certificatebasedauthconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/chat?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/communications-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/complianceapioverview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-externalconnection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contract?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/copilot-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/datapolicyoperation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-apps-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-device-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/directory?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domaindnsrecord?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domain?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/drive?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/education-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/employee-experience-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-external?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/filter-query-parameter
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/grouplifecyclepolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsetting?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsettingtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/identitycontainer?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/informationprotection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/invitation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/users?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/oauth2permissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/resourcespecificpermissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/place?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/planner-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/policy-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/print?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/privacy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/report?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/rolemanagement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/scopedrolemembership?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/search-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/serviceprincipal?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/shares?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sharepoint?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/solutions-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/filestorage?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscribedsku?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamwork?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/tenantrelationship?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/auth/auth-concepts
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/workplace?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sitepage?view=graph-rest-1.0

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/microsoft-graph-serviceprincipals-serviceprincipal-actions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

microsoft-graph-serviceprincipals-serviceprincipal-actions-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Microsoft Graph Admin Admin.admin Service Principals.service Principal.Actions API
  description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID.

    This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations,

    site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements,

    SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.'
  version: 1.0.0
  contact:
    name: Microsoft Graph API Support
    url: https://developer.microsoft.com/graph
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph API v1.0 endpoint
tags:
- name: servicePrincipals.servicePrincipal.Actions
  x-ms-docs-toc-type: container
paths:
  /servicePrincipals/{servicePrincipal-id}/addKey:
    description: Provides operations to call the addKey method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action addKey
      description: 'Adds a key credential to a servicePrincipal. This method along with removeKey can be used by a servicePrincipal to automate rolling its expiring keys. As part of the request validation for this method, a proof of possession of an existing key is verified before the action can be performed.  ServicePrincipals that don''t have any existing valid certificates (i.e.: no certificates have been added yet, or all certificates have expired), won''t be able to use this service action. Update servicePrincipal can be used to perform an update instead.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-addkey?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.addKey
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                keyCredential:
                  $ref: '#/components/schemas/microsoft.graph.keyCredential'
                passwordCredential:
                  anyOf:
                  - $ref: '#/components/schemas/microsoft.graph.passwordCredential'
                  - type: object
                    nullable: true
                proof:
                  type: string
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.keyCredential'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /servicePrincipals/{servicePrincipal-id}/addPassword:
    description: Provides operations to call the addPassword method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action addPassword
      description: Add a strong password or secret to a servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-addpassword?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.addPassword
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                passwordCredential:
                  anyOf:
                  - $ref: '#/components/schemas/microsoft.graph.passwordCredential'
                  - type: object
                    nullable: true
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.passwordCredential'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /servicePrincipals/{servicePrincipal-id}/addTokenSigningCertificate:
    description: Provides operations to call the addTokenSigningCertificate method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action addTokenSigningCertificate
      description: "Create a self-signed signing certificate and return a selfSignedCertificate object, which is the public part of the generated certificate.  The self-signed signing certificate is composed of the following objects, which are added to the servicePrincipal: \n+ The keyCredentials object with the following objects:\n    + A private key object with usage set to Sign.\n    + A public key object with usage set to Verify.\n+ The passwordCredentials object.  All the objects have the same value of customKeyIdentifier. The passwordCredential is used to open the PFX file (private key). It and the associated private key object have the same value of keyId. When set during creation through the displayName property, the subject of the certificate cannot be updated. The startDateTime is set to the same time the certificate is created using the action. The endDateTime can be up to three years after the certificate is created."
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-addtokensigningcertificate?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.addTokenSigningCertificate
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                displayName:
                  type: string
                  nullable: true
                endDateTime:
                  pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
                  type: string
                  format: date-time
                  nullable: true
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.selfSignedCertificate'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /servicePrincipals/{servicePrincipal-id}/checkMemberGroups:
    description: Provides operations to call the checkMemberGroups method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action checkMemberGroups
      description: 'Check for membership in a specified list of group IDs, and return from that list the IDs of groups where a specified object is a member. The specified object can be of one of the following types:

        - user

        - group

        - service principal

        - organizational contact

        - device

        - directory object This function is transitive. You can check up to a maximum of 20 groups per request. This function supports all groups provisioned in Microsoft Entra ID. Because Microsoft 365 groups cannot contain other groups, membership in a Microsoft 365 group is always direct.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-checkmembergroups?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.checkMemberGroups
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                groupIds:
                  type: array
                  items:
                    type: string
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                allOf:
                - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
                - type: object
                  properties:
                    value:
                      type: array
                      items:
                        type: string
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /servicePrincipals/{servicePrincipal-id}/checkMemberObjects:
    description: Provides operations to call the checkMemberObjects method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action checkMemberObjects
      operationId: servicePrincipals.servicePrincipal.checkMemberObjects
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                ids:
                  type: array
                  items:
                    type: string
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                allOf:
                - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
                - type: object
                  properties:
                    value:
                      type: array
                      items:
                        type: string
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /servicePrincipals/{servicePrincipal-id}/getMemberGroups:
    description: Provides operations to call the getMemberGroups method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action getMemberGroups
      description: Return all the group IDs for the groups that the specified user, group, service principal, organizational contact, device, or directory object is a member of. This function is transitive. This API returns up to 11,000 group IDs. If more than 11,000 results are available, it returns a 400 Bad Request error with the DirectoryResultSizeLimitExceeded error code. If you get the DirectoryResultSizeLimitExceeded error code, use the List group transitive memberOf API instead.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getmembergroups?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.getMemberGroups
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                securityEnabledOnly:
                  type: boolean
                  default: false
                  nullable: true
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                allOf:
                - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
                - type: object
                  properties:
                    value:
                      type: array
                      items:
                        type: string
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /servicePrincipals/{servicePrincipal-id}/getMemberObjects:
    description: Provides operations to call the getMemberObjects method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action getMemberObjects
      description: 'Return all IDs for the groups, administrative units, and directory roles that an object of one of the following types is a member of:

        - user

        - group

        - service principal

        - organizational contact

        - device

        - directory object This function is transitive. Only users and role-enabled groups can be members of directory roles.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getmemberobjects?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.getMemberObjects
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                securityEnabledOnly:
                  type: boolean
                  default: false
                  nullable: true
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                allOf:
                - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
                - type: object
                  properties:
                    value:
                      type: array
                      items:
                        type: string
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /servicePrincipals/{servicePrincipal-id}/removeKey:
    description: Provides operations to call the removeKey method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action removeKey
      description: Remove a key credential from a servicePrincipal. This method along with addKey can be used by a servicePrincipal to automate rolling its expiring keys. As part of the request validation for this method, a proof of possession of an existing key is verified before the action can be performed.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-removekey?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.removeKey
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                keyId:
                  pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
                  type: string
                  format: uuid
                proof:
                  type: string
        required: true
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /servicePrincipals/{servicePrincipal-id}/removePassword:
    description: Provides operations to call the removePassword method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action removePassword
      description: Remove a password from a servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-removepassword?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.removePassword
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                keyId:
                  pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
                  type: string
                  format: uuid
        required: true
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /servicePrincipals/{servicePrincipal-id}/restore:
    description: Provides operations to call the restore method.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action restore
      description: 'Restore a recently deleted application, group, servicePrincipal, administrative unit, or user object from deleted items.  Restore a recently deleted directory object from deleted items. The following types are supported:

        - administrativeUnit

        - application

        - certificateBasedAuthPki

        - certificateAuthorityDetail

        - group

        - servicePrincipal

        - user If an item is accidentally deleted, you can fully restore the item. Additionally, restoring an application doesn''t automatically restore the associated service principal automatically. You must call this API to explicitly restore the deleted service principal. A recently deleted item remains available for up to 30 days. After 30 days, the item is permanently deleted.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directory-deleteditems-restore?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.restore
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                anyOf:
                - $ref: '#/components/schemas/microsoft.graph.directoryObject'
                - type: object
                  nullable: true
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /servicePrincipals/getAvailableExtensionProperties:
    description: Provides operations to call the getAvailableExtensionProperties method.
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action getAvailableExtensionProperties
      description: 'Return all directory extension definitions that are registered in a directory, including through multitenant apps. The following entities support extension properties:'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getavailableextensionproperties?view=graph-rest-1.0
      operationId: servicePrincipals.getAvailableExtensionProperties
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                isSyncedFromOnPremises:
                  type: boolean
                  default: false
                  nullable: true
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                title: Collection of extensionProperty
                type: object
                allOf:
                - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
                - type: object
                  properties:
                    value:
                      type: array
                      items:
                        $ref: '#/components/schemas/microsoft.graph.extensionProperty'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /servicePrincipals/getByIds:
    description: Provides operations to call the getByIds method.
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action getByIds
      description: 'Return the directory objects specified in a list of IDs. Only a subset of user properties are returned by default in v1.0. Some common uses for this function are to:'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getbyids?view=graph-rest-1.0
      operationId: servicePrincipals.getByIds
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                ids:
                  type: array
                  items:
                    type: string
                types:
                  type: array
                  items:
                    type: string
                    nullable: true
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                title: Collection of directoryObject
                type: object
                allOf:
                - $ref: '#/components/schemas/BaseCollectionPaginationCountResponse'
                - type: object
                  properties:
                    value:
                      type: array
                      items:
                        $ref: '#/components/schemas/microsoft.graph.directoryObject'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /servicePrincipals/validateProperties:
    description: Provides operations to call the validateProperties method.
    post:
      tags:
      - servicePrincipals.servicePrincipal.Actions
      summary: Microsoft Graph Invoke action validateProperties
      description: 'Validate that a Microsoft 365 group''s display name or mail nickname complies with naming policies. Clients can use this API to determine whether a display name or mail nickname is valid before trying to create a Microsoft 365 group. To validate the properties of an existing group, use the group: validateProperties function. The following policy validations are performed for the display name and mail nickname properties:

        1. Validate the prefix and suffix naming policy

        2. Validate the custom banned words policy

        3. Validate that the mail nickname is unique This API only returns the first validation failure that is encountered. If the properties fail multiple validations, only the first validation failure is returned. However, you can validate both the mail nickname and the display name and receive a collection of validation errors if you''re only validating the prefix and suffix naming policy. To learn more about configuring naming policies, see Configure naming policy.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-validateproperties?view=graph-rest-1.0
      operationId: servicePrincipals.validateProperties
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                entityType:
                  type: string
                  nullable: true
                displayName:
                  type: string
                  nullable: true
                mailNickname:
                  type: string
                  nullable: true
                onBehalfOfUserId:
                  pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
                  type: string
                  format: uuid
                  nullable: true
        required: true
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
components:
  schemas:
    microsoft.graph.selfSignedCertificate:
      title: selfSignedCertificate
      required:
      - '@odata.type'
      type: object
      properties:
        customKeyIdentifier:
          type: string
          description: Custom key identifier.
          format: base64url
          nullable: true
        displayName:
          type: string
          description: The friendly name for the key.
          nullable: true
        endDateTime:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: The date and time at which the credential expires. The timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on January 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
          nullable: true
        key:
          type: string
          description: The value for the key credential. Should be a Base-64 encoded value.
          format: base64url
          nullable: true
        keyId:
          pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
          type: string
          description: The unique identifier (GUID) for the key.
          format: uuid
          nullable: true
        startDateTime:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: The date and time at which the credential becomes valid. The timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on January 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
          nullable: true
        thumbprint:
          type: string
          description: The thumbprint value for the key.
          nullable: true
        type:
          type: string
          description: The type of key credential. AsymmetricX509Cert.
          nullable: true
        usage:
          type: string
          description: A string that describes the purpose for which the key can be used. The possible value is Verify.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type: string
          nullable: true
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        required:
        - '@odata.type'
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
            nullable: true
          '@odata.type':
            type: string
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.administrativeUnit': '#/components/schemas/microsoft.graph.administrativeUnit'
            '#microsoft.graph.application': '#/components/schemas/microsoft.graph.application'
            '#microsoft.graph.appRoleAssignment': '#/components/schemas/microsoft.graph.appRoleAssignment'
            '#microsoft.graph.certificateAuthorityDetail': '#/components/schemas/microsoft.graph.certificateAuthorityDetail'
            '#microsoft.graph.certificateBasedAuthPki': '#/components/schemas/microsoft.graph.certificateBasedAuthPki'
            '#microsoft.graph.contract': '#/components/schemas/microsoft.graph.contract'
            '#microsoft.graph.device': '#/components/schemas/microsoft.graph.device'
            '#microsoft.graph.directoryObjectPartnerReference': '#/components/schemas/microsoft.graph.directoryObjectPartnerReference'
            '#microsoft.graph.directoryRole': '#/components/schemas/microsoft.graph.directoryRole'
            '#microsoft.graph.directoryRoleTemplate': '#/components/schemas/microsoft.graph.directoryRoleTemplate'
            '#microsoft.graph.endpoint': '#/components/schemas/microsoft.graph.endpoint'
            '#microsoft.graph.extensionProperty': '#/components/schemas/microsoft.graph.extensionProperty'
            '#microsoft.graph.group': '#/components/schemas/microsoft.graph.group'
            '#microsoft.graph.groupSettingTemplate': '#/components/schemas/microsoft.graph.groupSettingTemplate'
            '#microsoft.graph.multiTenantOrganizationMember': '#/components/schemas/microsoft.graph.multiTenantOrganizationMember'
            '#microsoft.graph.organization': '#/components/schemas/microsoft.graph.organization'
            '#microsoft.graph.orgContact': '#/components/schemas/microsoft.graph.orgContact'
            '#microsoft.graph.policyBase': '#/components/schemas/microsoft.graph.policyBase'
            '#microsoft.graph.appManagementPolicy': '#/components/schemas/microsoft.graph.appManagementPolicy'
            '#microsoft.graph.authorizationPolicy': '#/components/schemas/microsoft.graph.authorizationPolicy'
            '#microsoft.graph.crossTenantAccessPolicy': '#/components/schemas/microsoft.graph.crossTenantAccessPolicy'
            '#microsoft.graph.identitySecurityDefaultsEnforcementPolicy': '#/components/schemas/microsoft.graph.identitySecurityDefaultsEnforcementPolicy'
            '#microsoft.graph.permissionGrantPolicy': '#/componen

# --- truncated at 32 KB (163 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/microsoft-graph/refs/heads/main/openapi/microsoft-graph-serviceprincipals-serviceprincipal-actions-api-openapi.yml