Microsoft Graph servicePrincipals.servicePrincipal API

The servicePrincipals.servicePrincipal API from Microsoft Graph — 4 operation(s) for serviceprincipals.serviceprincipal.

Operations 9

GET /servicePrincipals Microsoft Graph List servicePrincipals #
POST /servicePrincipals Microsoft Graph Create servicePrincipal #
GET /servicePrincipals/{servicePrincipal-id} Microsoft Graph Get servicePrincipal #
PATCH /servicePrincipals/{servicePrincipal-id} Microsoft Graph Upsert servicePrincipal #
DELETE /servicePrincipals/{servicePrincipal-id} Microsoft Graph Delete servicePrincipal #
GET /servicePrincipals(appId='{appId}') Microsoft Graph Get servicePrincipal #
PATCH /servicePrincipals(appId='{appId}') Microsoft Graph Upsert servicePrincipal #
DELETE /servicePrincipals(appId='{appId}') Microsoft Graph Delete servicePrincipal #
GET /servicePrincipals/$count Microsoft Graph Get the number of the resource #

Documentation

📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/admin?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreementacceptance?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/agreement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamsapp?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/applicationtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethodspolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/certificatebasedauthconfiguration?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/chat?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/communications-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/complianceapioverview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-externalconnection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/contract?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/copilot-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/datapolicyoperation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-apps-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/intune-device-conceptual?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/directory?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domaindnsrecord?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/domain?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/drive?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/education-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/employee-experience-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/externalconnectors-external?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/filter-query-parameter
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/grouplifecyclepolicy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsetting?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/groupsettingtemplate?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/identitycontainer?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/informationprotection?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/invitation?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/users?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/oauth2permissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/resourcespecificpermissiongrant?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/place?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/planner-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/policy-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/print?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/privacy?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/report?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/rolemanagement?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/scopedrolemembership?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/search-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/serviceprincipal?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/shares?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sharepoint?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/solutions-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/filestorage?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscribedsku?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/teamwork?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/tenantrelationship?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/auth/auth-concepts
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/workplace?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0
📖
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/sitepage?view=graph-rest-1.0

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/microsoft-graph-serviceprincipals-serviceprincipal-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

microsoft-graph-serviceprincipals-serviceprincipal-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Microsoft Graph Admin Admin.admin Service Principals.service Principal API
  description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID.

    This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations,

    site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements,

    SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.'
  version: 1.0.0
  contact:
    name: Microsoft Graph API Support
    url: https://developer.microsoft.com/graph
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph API v1.0 endpoint
tags:
- name: servicePrincipals.servicePrincipal
  x-ms-docs-toc-type: page
paths:
  /servicePrincipals:
    description: Provides operations to manage the collection of servicePrincipal entities.
    get:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph List servicePrincipals
      description: Retrieve a list of servicePrincipal objects.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-list?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.ListServicePrincipal
      parameters:
      - name: ConsistencyLevel
        in: header
        description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
        schema:
          type: string
        examples:
          example-1:
            description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
            value: eventual
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.servicePrincipalCollectionResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Create servicePrincipal
      description: Create a new servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-post-serviceprincipals?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.CreateServicePrincipal
      requestBody:
        description: New entity
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        required: true
      responses:
        2XX:
          description: Created entity
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /servicePrincipals/{servicePrincipal-id}:
    description: Provides operations to manage the collection of servicePrincipal entities.
    parameters:
    - name: servicePrincipal-id
      in: path
      description: The unique identifier of servicePrincipal
      required: true
      schema:
        type: string
      x-ms-docs-key-type: servicePrincipal
    get:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Get servicePrincipal
      description: Retrieve the properties and relationships of a servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-get?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.GetServicePrincipal
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved entity
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Upsert servicePrincipal
      description: Create a new servicePrincipal object if it doesn't exist, or update the properties of an existing servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-upsert?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.UpdateServicePrincipal
      requestBody:
        description: New property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Delete servicePrincipal
      description: Delete a servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-delete?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.DeleteServicePrincipal
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /servicePrincipals(appId='{appId}'):
    description: Provides operations to manage the collection of servicePrincipal entities.
    parameters:
    - name: appId
      in: path
      description: Alternate key of servicePrincipal
      required: true
      schema:
        type: string
        nullable: true
    get:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Get servicePrincipal
      description: Retrieve the properties and relationships of a servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-get?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.GetServicePrincipalByAppId
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved entity
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Upsert servicePrincipal
      description: Create a new servicePrincipal object if it doesn't exist, or update the properties of an existing servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-upsert?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.UpdateServicePrincipalByAppId
      requestBody:
        description: New property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.servicePrincipal'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Delete servicePrincipal
      description: Delete a servicePrincipal object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/serviceprincipal-delete?view=graph-rest-1.0
      operationId: servicePrincipals.servicePrincipal.DeleteServicePrincipalByAppId
      parameters:
      - name: If-Match
        in: header
        description: ETag
        schema:
          type: string
      responses:
        '204':
          description: Success
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /servicePrincipals/$count:
    description: Provides operations to count the resources in the collection.
    get:
      tags:
      - servicePrincipals.servicePrincipal
      summary: Microsoft Graph Get the number of the resource
      operationId: servicePrincipals.GetCount-da6d
      parameters:
      - name: ConsistencyLevel
        in: header
        description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
        schema:
          type: string
        examples:
          example-1:
            description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
            value: eventual
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        4XX:
          $ref: '#/components/responses/error'
        5XX:
          $ref: '#/components/responses/error'
components:
  schemas:
    ODataCountResponse:
      type: integer
      format: int32
    microsoft.graph.mutability:
      title: mutability
      enum:
      - ReadWrite
      - ReadOnly
      - Immutable
      - WriteOnly
      type: string
    microsoft.graph.filterClause:
      title: filterClause
      required:
      - '@odata.type'
      type: object
      properties:
        operatorName:
          type: string
          description: Name of the operator to be applied to the source and target operands. Must be one of the supported operators. Supported operators can be discovered.
          nullable: true
        sourceOperandName:
          type: string
          description: Name of source operand (the operand being tested). The source operand name must match one of the attribute names on the source object.
          nullable: true
        targetOperand:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.filterOperand'
          - type: object
            nullable: true
          description: Values that the source operand will be tested against.
        '@odata.type':
          type: string
    microsoft.graph.attributeMapping:
      title: attributeMapping
      required:
      - '@odata.type'
      type: object
      properties:
        defaultValue:
          type: string
          description: Default value to be used in case the source property was evaluated to null. Optional.
          nullable: true
        exportMissingReferences:
          type: boolean
          description: For internal use only.
        flowBehavior:
          $ref: '#/components/schemas/microsoft.graph.attributeFlowBehavior'
        flowType:
          $ref: '#/components/schemas/microsoft.graph.attributeFlowType'
        matchingPriority:
          maximum: 2147483647
          minimum: -2147483648
          type: number
          description: If higher than 0, this attribute will be used to perform an initial match of the objects between source and target directories. The synchronization engine will try to find the matching object using attribute with lowest value of matching priority first. If not found, the attribute with the next matching priority will be used, and so on a until match is found or no more matching attributes are left. Only attributes that are expected to have unique values, such as email, should be used as matching attributes.
          format: int32
        source:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.attributeMappingSource'
          - type: object
            nullable: true
          description: Defines how a value should be extracted (or transformed) from the source object.
        targetAttributeName:
          type: string
          description: Name of the attribute on the target object.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.referencedObject:
      title: referencedObject
      required:
      - '@odata.type'
      type: object
      properties:
        referencedObjectName:
          type: string
          description: Name of the referenced object. Must match one of the objects in the directory definition.
          nullable: true
        referencedProperty:
          type: string
          description: Currently not supported. Name of the property in the referenced object, the value for which is used as the reference.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.keyCredential:
      title: keyCredential
      required:
      - '@odata.type'
      type: object
      properties:
        customKeyIdentifier:
          type: string
          description: A 40-character binary type that can be used to identify the credential. Optional. When not provided in the payload, defaults to the thumbprint of the certificate.
          format: base64url
          nullable: true
        displayName:
          type: string
          description: The friendly name for the key, with a maximum length of 90 characters. Longer values are accepted but shortened. Optional.
          nullable: true
        endDateTime:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: The date and time at which the credential expires. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
          nullable: true
        key:
          type: string
          description: The certificate's raw data in byte array converted to Base64 string. Returned only on $select for a single object, that is, GET applications/{applicationId}?$select=keyCredentials or GET servicePrincipals/{servicePrincipalId}?$select=keyCredentials; otherwise, it's always null.  From a .cer certificate, you can read the key using the Convert.ToBase64String() method. For more information, see Get the certificate key.
          format: base64url
          nullable: true
        keyId:
          pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
          type: string
          description: The unique identifier (GUID) for the key.
          format: uuid
          nullable: true
        startDateTime:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: The date and time at which the credential becomes valid.The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
          nullable: true
        type:
          type: string
          description: The type of key credential; for example, Symmetric, AsymmetricX509Cert.
          nullable: true
        usage:
          type: string
          description: A string that describes the purpose for which the key can be used; for example, Verify.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.ODataErrors.InnerError:
      title: InnerError
      required:
      - '@odata.type'
      type: object
      properties:
        request-id:
          type: string
          description: Request Id as tracked internally by the service
          nullable: true
        client-request-id:
          type: string
          description: Client request Id as sent by the client application.
          nullable: true
        date:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date when the error occured.
          format: date-time
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.samlSingleSignOnSettings:
      title: samlSingleSignOnSettings
      required:
      - '@odata.type'
      type: object
      properties:
        relayState:
          type: string
          description: The relative URI the service provider would redirect to after completion of the single sign-on flow.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.synchronizationQuarantine:
      title: synchronizationQuarantine
      required:
      - '@odata.type'
      type: object
      properties:
        currentBegan:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date and time when the quarantine was last evaluated and imposed. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
        error:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.synchronizationError'
          - type: object
            nullable: true
          description: Describes the error(s) that occurred when putting the synchronization job into quarantine.
        nextAttempt:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date and time when the next attempt to re-evaluate the quarantine will be made. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
        reason:
          $ref: '#/components/schemas/microsoft.graph.quarantineReason'
        seriesBegan:
          pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
          type: string
          description: Date and time when the quarantine was first imposed in this series (a series starts when a quarantine is first imposed, and is reset as soon as the quarantine is lifted). The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
          format: date-time
        seriesCount:
          type: number
          description: Number of times in this series the quarantine was re-evaluated and left in effect (a series starts when quarantine is first imposed, and is reset as soon as quarantine is lifted).
          format: int64
        '@odata.type':
          type: string
    microsoft.graph.remoteDesktopSecurityConfiguration:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: remoteDesktopSecurityConfiguration
        required:
        - '@odata.type'
        type: object
        properties:
          isRemoteDesktopProtocolEnabled:
            type: boolean
            description: Determines if Microsoft Entra ID RDS authentication protocol for RDP is enabled.
          targetDeviceGroups:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup'
            description: The collection of target device groups that are associated with the RDS security configuration that will be enabled for SSO when a client connects to the target device over RDP using the new Microsoft Entra ID RDS authentication protocol. <br/<Supports $expand.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.remoteDesktopSecurityConfiguration'
    microsoft.graph.keyValuePair:
      title: keyValuePair
      required:
      - '@odata.type'
      type: object
      properties:
        name:
          type: string
          description: Name for this key-value pair
        value:
          type: string
          description: Value for this key-value pair
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.objectDefinitionMetadataEntry:
      title: objectDefinitionMetadataEntry
      required:
      - '@odata.type'
      type: object
      properties:
        key:
          anyOf:
          - $ref: '#/components/schemas/microsoft.graph.objectDefinitionMetadata'
          - type: object
            nullable: true
          description: 'The possible values are: PropertyNameAccountEnabled, PropertyNameSoftDeleted, IsSoftDeletionSupported, IsSynchronizeAllSupported, ConnectorDataStorageRequired, Extensions, LinkTypeName.'
        value:
          type: string
          description: Value of the metadata property.
          nullable: true
        '@odata.type':
          type: string
    microsoft.graph.objectDefinition:
      title: objectDefinition
      required:
      - '@odata.type'
      type: object
      properties:
        attributes:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.attributeDefinition'
          description: Defines attributes of the object.
        metadata:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.objectDefinitionMetadataEntry'
          description: Metadata for the given object.
        name:
          type: string
          description: Name of the object. Must be unique within a directory definition. Not nullable.
          nullable: true
        supportedApis:
          type: array
          items:
            type: string
            nullable: true
          description: The API that the provisioning service queries to retrieve data for synchronization.
        '@odata.type':
          type: string
    microsoft.graph.oAuth2PermissionGrant:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: oAuth2PermissionGrant
        required:
        - '@odata.type'
        type: object
        properties:
          clientId:
            type: string
            description: The object id (not appId) of the client service principal for the application that's authorized to act on behalf of a signed-in user when accessing an API. Required. Supports $filter (eq only).
          consentType:
            type: string
            description: Indicates if authorization is granted for the client application to impersonate all users or only a specific user. AllPrincipals indicates authorization to impersonate all users. Principal indicates authorization to impersonate a specific user. Consent on behalf of all users can be granted by an administrator. Nonadmin users might be authorized to consent on behalf of themselves in some cases, for some delegated permissions. Required. Supports $filter (eq only).
            nullable: true
          principalId:
            type: string
            description: The id of the user on behalf of whom the client is authorized to access the resource, when consentType is Principal. If consentType is AllPrincipals this value is null. Required when consentType is Principal. Supports $filter (eq only).
            nullable: true
          resourceId:
            type: string
            description: The id of the resource service principal to which access is authorized. This identifies the API that the client is authorized to attempt to call on behalf of a signed-in user. Supports $filter (eq only).
          scope:
            type: string
            description: A space-separated list of the claim values for delegated permissions that should be included in access tokens for the resource application (the API). For example, openid User.Read GroupMember.Read.All. Each claim value should match the value field of one of the delegated permissions defined by the API, listed in the oauth2PermissionScopes property of the resource service principal. Must not exceed 3,850 characters in length.
            nullable: true
          '@odata.type':
            type: string
      x-ms-discriminator-value: '#microsoft.graph.oAuth2PermissionGrant'
    microsoft.graph.appManagementPolicy:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.policyBase'
      - title: appManagementPolicy
        required:
        - '@odata.type'
        type: object
        properties:
          isEnabled:
            type: boolean
            description: Denotes whether the policy is enabled.
          restrictions:
            anyOf:
            - $ref: '#/components/schemas/microsoft.graph.customAppManagementConfiguration'
            - type: object
              nullable: true
            description: Restrictions that apply to an application or service principal object.
          appliesTo:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.directoryObject'
            description: Collection of applications and service principals to which the policy is applied.
            x-ms-navigationProperty: true
          '@odata.type':
            type: string
            default: '#microsoft.graph.appManagementPolicy'
      x-ms-discriminator-value: '#microsoft.graph.appManagementPolicy'
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        required:
        - '@odata.type'
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type: string
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
            nullable: true
          '@odata.type':
            type: string
        discriminator:
          propertyName: '@odata.type'
          mapping:
            '#microsoft.graph.administrativeUnit': '#/components/schemas/microsoft.graph.administrativeUnit'
            '#microsoft.graph.application': '#/components/schemas/microsoft.graph.application'
            '#microsoft.graph.appRoleAssignment': '#/components/schemas/microsoft.graph.appRoleAssignment'
            '#microsoft.graph.certificateAuthorityDetail': '#/components/schemas/microsoft.graph.certificateAuthorityDetail'
            '#microsoft.graph.certificateBasedAuthPki': '#/components/schemas/microsoft.graph.certificateBasedAuthPki'
            '#microsoft.graph.contract': '#/components/schemas/microsoft.graph.contract'
            '#microsoft.graph.device': '#/components/schemas/microsoft.graph.device'
            '#microsoft.graph.directoryObjectPartnerReference': '#/components/schemas/microsoft.graph.directoryObjectPartnerReference'
            '#microsoft.graph.directoryRole': '#/components/schemas/microsoft.graph.directoryRole'
            '#microsoft.graph.directoryRoleTemplate': '#/components/schemas/microsoft.graph.directoryRoleTemplate'
            '#microsoft.graph.endpoint': '#/components/schemas/microsoft.graph.endpoint'
            '#microsoft.graph.extensionProperty': '#/components/schemas/microsoft.graph.extensionProperty'
            '#microsoft.graph.group': '#/components/schemas/microsoft.graph.group'
            '#microsoft.graph.groupSettingTemplate': '#/components/schemas/microsoft.graph.groupSettingTemplate'
            '#microsoft.graph.multiTenantOrganizationMember': '#/components/schemas/microsoft.graph.multiTenantOrganizationMember'
            '#microsoft.graph.organization': '#/components/schemas/microsoft.graph.organization'
            '#microsoft.graph.orgContact': '#/components/schemas/microsoft.graph.orgContact'
            '#microsoft.graph.policyBase': '#/components/schemas/microsoft.graph.policyBase'
            '#microsoft.graph.appManagementPolicy': '#/components/schemas/microsoft.graph.appManagementPolicy'
            '#microsoft.graph.authorizationPolicy': '#/components/schemas/microsoft.graph.authorizationPolicy'
            '#microsoft.graph.crossTenantAccessPolicy': '#/components/schemas/microsoft.graph.crossTenantAccessPolicy'
            '#microsoft.graph.identitySecurityDefaultsEnforcementPolicy': '#/components/schemas/microsoft.graph.identitySecurityDefaultsEnforcementPolicy'
            '#microsoft.graph.permissionGrantPolicy': '#/components/schemas/microsoft.graph.permissionGrantPolicy'
            '#microsoft.graph.stsPolicy': '#/components/schemas/microsoft.graph.stsPolicy'
            '#microsoft.graph.activityBasedTimeoutPolicy': '#/components/schemas/microsoft.graph.activityBasedTimeoutPolicy'
            '#microsoft.graph.claimsMappingPolicy': '#/components/schemas/microsoft.graph.claimsMappingPolicy'
            '#microsoft.graph.homeRealmDiscoveryPolicy': '#/components/schemas/microsoft.graph.homeRealmDiscoveryPolicy'
            '#microsoft.graph.tokenIssuancePolicy': '#/components/schemas/microsoft.graph.tokenIssuancePolicy'
            '#microsoft.graph.tokenLifetimePolicy': '#/components/schemas/microsoft.graph.tokenLifetimePolicy'
            '#microsoft.graph.tenantAppManagementPolicy': '#/components/schemas/microsoft.graph.tenantAppManagementPolicy'
            '#microsoft.graph.resourceSpecificPermissionGrant': '#/components/sc

# --- truncated at 32 KB (243 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/microsoft-graph/refs/heads/main/openapi/microsoft-graph-serviceprincipals-serviceprincipal-api-openapi.yml