Juniper Mist AI Orgs Security Policies API

Security Policy is designed to audit / catch discrepancies between "what's intended to be running" versus "what's actually running" in a network. Many big organizations have separated Security and IT team (for good reasons). Each site can be assigned a security policy. Whenever an AP is provisioned, the configuration will be checked against the security policy. Any violations will be flagged in [Device Config History](/#operations/searchSiteDeviceConfigHistory) where you can search for the when and where the violation occurs.

OpenAPI Specification

mist-ai-orgs-security-policies-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: tmunzer@juniper.net
    name: Thomas Munzer
  description: '> Version: **2604.1.1**

    >

    > Date: **May 13, 2026**

    <div class="notification"> NOTE:<br>Some important API changes will be introduced. Please make sure to read the <a href="https://www.juniper.net/documentation/us/en/software/mist/api/http/guides/important-api-changes">announcements</a> </div>


    ---

    ## Additional Documentation

    * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)

    * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)

    * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)


    ## Helpful Resources

    * [API Sandbox and Exercises](https://api-class.mist.com/)

    * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)

    * [Python Script Examples](https://github.com/tmunzer/mist_library)

    * [API Demo Apps](https://apps.mist-lab.fr/)

    * [Juniper Blog](https://blogs.juniper.net/)


    ## Mist Web Browser Extension:

    * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)

    * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)


    ---'
  license:
    name: MIT
    url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
  title: Mist Admins Orgs Security Policies API
  version: 2604.1.1
  x-logo:
    altText: Juniper-MistAI
    backgroundColor: '#FFFFFF'
    url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
  url: https://api.mist.com
- description: Mist Global 02
  url: https://api.gc1.mist.com
- description: Mist Global 03
  url: https://api.ac2.mist.com
- description: Mist Global 04
  url: https://api.gc2.mist.com
- description: Mist Global 05
  url: https://api.gc4.mist.com
- description: Mist EMEA 01
  url: https://api.eu.mist.com
- description: Mist EMEA 02
  url: https://api.gc3.mist.com
- description: Mist EMEA 03
  url: https://api.ac6.mist.com
- description: Mist EMEA 04
  url: https://api.gc6.mist.com
- description: Mist APAC 01
  url: https://api.ac5.mist.com
- description: Mist APAC 02
  url: https://api.gc5.mist.com
- description: Mist APAC 03
  url: https://api.gc7.mist.com
security:
- apiToken: []
- basicAuth: []
- basicAuth: []
  csrfToken: []
tags:
- description: "Security Policy is designed to audit / catch discrepancies between\n\"what's intended to be running\" versus \"what's actually running\" in a network. \n\nMany big organizations have separated Security and IT team (for good reasons). Each site can be assigned a security policy.\n Whenever an AP is provisioned, the configuration will be checked against the security policy.\n Any violations will be flagged in [Device Config History](/#operations/searchSiteDeviceConfigHistory) where you can search for the when and where the violation occurs."
  name: Orgs Security Policies
paths:
  /api/v1/orgs/{org_id}/secpolicies:
    parameters:
    - $ref: '#/components/parameters/org_id'
    get:
      description: Get List of Org Security Policies
      operationId: listOrgSecPolicies
      parameters:
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/page'
      responses:
        '200':
          $ref: '#/components/responses/SecpoliciesArray'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: listOrgSecPolicies
      tags:
      - Orgs Security Policies
    post:
      description: Create Org Security Policy
      operationId: createOrgSecPolicy
      requestBody:
        content:
          application/json:
            examples:
              Example:
                value:
                  name: string
                  wlans:
                  - acct_immediate_update: false
                    acct_interim_interval: 0
                    acct_servers:
                    - host: 1.2.3.4
                      keywrap_enabled: true
                      keywrap_format: hex
                      keywrap_kek: '1122334455'
                      keywrap_mack: '1122334455'
                      port: 1813
                      secret: testing123
                    allow_ipv6_ndp: true
                    allow_mdns: false
                    allow_ssdp: false
                    app_limit:
                      apps:
                        dropbox: 300
                        netflix: 60
                      enabled: false
                      wxtag_ids:
                        f99862d9-2726-931f-7559-3dfdf5d070d3: 30
                    app_qos:
                      apps:
                        skype-business-video:
                          dscp: 32
                          dst_subnet: 10.2.0.0/16
                          src_subnet: 10.2.0.0/16
                      enabled: true
                      others:
                      - dscp: 32
                        dst_subnet: 10.2.0.0/16
                        port_ranges: 80,1024-6553
                        protocol: udp
                        src_subnet: 10.2.0.0/16
                    arp_filter: false
                    auth:
                      anticlog_threshold: 16
                      eap_reauth: false
                      enable_mac_auth: false
                      key_idx: 1
                      keys:
                      - string
                      multi_psk_only: false
                      pairwise:
                      - wpa2-ccmp
                      private_wlan: true
                      psk: foryoureyesonly
                      type: psk
                      wep_as_secondary_auth: true
                    auth_server_selection: ordered
                    auth_servers:
                    - host: 1.2.3.4
                      keywrap_enabled: true
                      keywrap_format: hex
                      keywrap_kek: '1122334455'
                      keywrap_mack: '1122334455'
                      port: 1812
                      secret: testing123
                    auth_servers_nas_id: 5c5b350e0101-nas
                    auth_servers_nas_ip: 15.3.1.5
                    auth_servers_retries: 5
                    auth_servers_timeout: 5
                    band: string
                    band_steer: false
                    band_steer_force_band5: false
                    bands:
                    - '24'
                    - '5'
                    block_blacklist_clients: false
                    bonjour:
                      additional_vlan_ids: 10,20
                      enabled: false
                      services:
                        airplay:
                          radius_groups:
                          - teachers
                          scope: same_ap
                    cisco_cwa:
                      allowed_hostnames:
                      - snapchat.com
                      allowed_subnets:
                      - 63.5.3.0/24
                      blocked_subnets:
                      - 192.168.0.0/16
                      enabled: false
                    client_limit_down: 1000
                    client_limit_down_enabled: false
                    client_limit_up: 512
                    client_limit_up_enabled: false
                    coa_servers:
                    - disable_event_timestamp_check: false
                      enabled: false
                      ip: 1.2.3.4
                      port: 3799
                      secret: testing456
                    disable_11ax: false
                    disable_ht_vht_rates: false
                    disable_uapsd: false
                    disable_v1_roam_notify: false
                    disable_v2_roam_notify: false
                    disable_wmm: false
                    dns_server_rewrite:
                      enabled: false
                      radius_groups:
                        contractor: 172.1.1.1
                        guest: 8.8.8.8
                    dtim: 2
                    dynamic_psk:
                      default_psk: foryoureyesonly
                      default_vlan_id: 999
                      enabled: false
                      source: cloud_psks
                    dynamic_vlan:
                      default_vlan_id: 999
                      enabled: false
                      local_vlan_ids:
                      - 1
                      type: airespace-interface-name
                      vlans:
                        '131': default
                        '322': fast,video
                    enable_local_keycaching: false
                    enable_wireless_bridging: false
                    enabled: true
                    fast_dot1x_timers: false
                    hide_ssid: false
                    hostname_ie: false
                    hotspot20:
                      domain_name:
                      - mist.com
                      enabled: true
                      nai_realms:
                      - string
                      operators:
                      - google
                      - att
                      rcoi:
                      - 5A03BA0000
                      venue_name: some_name
                    interface: all
                    isolation: false
                    l2_isolation: false
                    legacy_overds: false
                    limit_bcast: false
                    limit_probe_response: true
                    max_idletime: 1800
                    mist_nac:
                      enabled: false
                    no_static_dns: false
                    no_static_ip: false
                    portal:
                      amazon_client_id: string
                      amazon_client_secret: string
                      amazon_email_domains:
                      - string
                      amazon_enabled: false
                      auth: none
                      azure_client_id: string
                      azure_client_secret: string
                      azure_enabled: false
                      azure_tenant_id: string
                      broadnet_password: password
                      broadnet_sid: MIST
                      broadnet_user_id: juniper
                      bypass_when_cloud_down: false
                      clickatell_api_key: string
                      cross_site: false
                      email_enabled: true
                      enabled: false
                      expire: 1440
                      external_portal_url: string
                      facebook_client_id: string
                      facebook_client_secret: string
                      facebook_email_domains:
                      - string
                      facebook_enabled: false
                      forward: false
                      forward_url: https://abc.com/promotions
                      google_client_id: string
                      google_client_secret: string
                      google_email_domains:
                      - mydomain.edu
                      - mydomain.org
                      google_enabled: false
                      gupshup_password: string
                      gupshup_userid: string
                      microsoft_client_id: string
                      microsoft_client_secret: string
                      microsoft_email_domains:
                      - string
                      microsoft_enabled: false
                      passphrase_enabled: false
                      password: let me in
                      predefined_sponsors_enabled: true
                      privacy: true
                      puzzel_password: string
                      puzzel_service_id: string
                      puzzel_username: string
                      smsMessageFormat: string
                      sms_enabled: false
                      sms_provider: twilio
                      sponsor_auto_approve: false
                      sponsor_email_domains:
                      - reserved.net
                      - reserved.org
                      sponsor_enabled: false
                      sponsor_link_validity_duration: '30'
                      sponsor_notify_all: false
                      sponsor_status_notify: false
                      sponsors:
                        sponsor1@company.com: FirstName1 LastName1
                        sponsor2@company.com: FirstName2 LastName2
                      sso_default_role: string
                      sso_forced_role: string
                      sso_idp_cert: string
                      sso_idp_sign_algo: sha256
                      sso_idp_sso_url: string
                      sso_issuer: string
                      sso_nameid_format: email
                      telstra_client_id: string
                      telstra_client_secret: string
                      twilio_auth_token: af9dac44c344a875ab5d31cb7abcdefg
                      twilio_phone_number: '+18548888888'
                      twilio_sid: AC72ec6ba0ec5af30e6731c5e47abcdefgh
                    portal_allowed_hostnames:
                    - snapchat.com
                    - ibm.com
                    portal_allowed_subnets:
                    - 63.5.3.0/24
                    portal_denied_hostnames:
                    - msg.snapchat.com
                    qos:
                      class: best_effort
                      overwrite: false
                    radsec:
                      enabled: true
                      idle_timeout: 60
                      mxcluster_ids:
                      - 572586b7-f97b-a22b-526c-8b97a3f609c4
                      proxy_hosts:
                      - mxedge1.local
                      server_name: radsec.abc.com
                      servers:
                      - host: 1.1.1.1
                        port: 1812
                      use_mxedge: true
                      use_site_mxedge: false
                    rateset:
                      '24':
                        ht: 00ff00ff00ff
                        legacy:
                        - '6'
                        - '9'
                        - '12'
                        - '18'
                        - 24b
                        - '36'
                        - '48'
                        - '54'
                        min_rssi: -70
                        template: custom
                        vht: 03ff03ff03ff01ff
                      '5':
                        ht: 00ff00ff00ff
                        legacy:
                        - '6'
                        - '9'
                        - '12'
                        - '18'
                        - 24b
                        - '36'
                        - '48'
                        - '54'
                        min_rssi: -70
                        template: custom
                        vht: 03ff03ff03ff01ff
                    roam_mode: NONE
                    schedule:
                      enabled: false
                      hours:
                        fri: 09:00-17:00
                        mon: 09:00-17:00
                    sle_excluded: false
                    ssid: corporate
                    use_eapol_v1: false
                    vlan_enabled: false
                    vlan_ids:
                    - 3
                    - 4
                    - 5
                    vlan_pooling: false
                    wxtag_ids:
                    - 497f6eca-6276-4993-bfeb-53e4bbba6f08
                    wxtunnel_id: string
                    wxtunnel_remote_id: string
            schema:
              $ref: '#/components/schemas/secpolicy'
      responses:
        '200':
          $ref: '#/components/responses/Secpolicy'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: createOrgSecPolicy
      tags:
      - Orgs Security Policies
  /api/v1/orgs/{org_id}/secpolicies/{secpolicy_id}:
    parameters:
    - $ref: '#/components/parameters/org_id'
    - $ref: '#/components/parameters/secpolicy_id'
    delete:
      description: Delete Org Security Policy
      operationId: deleteOrgSecPolicy
      responses:
        '200':
          $ref: '#/components/responses/OK'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: deleteOrgSecPolicy
      tags:
      - Orgs Security Policies
    get:
      description: Get Org Security Policy
      operationId: getOrgSecPolicy
      responses:
        '200':
          $ref: '#/components/responses/Secpolicy'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: getOrgSecPolicy
      tags:
      - Orgs Security Policies
    put:
      description: Update Org Security Policy
      operationId: updateOrgSecPolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/secpolicy'
        description: Request Body
      responses:
        '200':
          $ref: '#/components/responses/Secpolicy'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: updateOrgSecPolicy
      tags:
      - Orgs Security Policies
components:
  schemas:
    wlan_mxtunnel_ids:
      description: When `interface`=`mxtunnel`, id of the Mist Tunnel
      format: uuid
      items:
        examples:
        - 08cd7499-5841-51c8-e663-fb16b6f3b45e
        type: string
      type: array
    wlan_cisco_cwa_allowed_hostnames:
      description: List of hostnames without http(s):// (matched by substring)
      items:
        examples:
        - snapchat.com
        type: string
      type: array
    coa_server:
      additionalProperties: false
      description: CoA Server
      properties:
        disable_event_timestamp_check:
          default: false
          description: Whether to disable Event-Timestamp Check
          type: boolean
        enabled:
          default: false
          type: boolean
        ip:
          examples:
          - 1.2.3.4
          format: ipv4
          type: string
        port:
          $ref: '#/components/schemas/radius_coa_port'
        secret:
          examples:
          - testing456
          type: string
      required:
      - ip
      - secret
      type: object
    strings:
      items:
        type: string
      type: array
      uniqueItems: true
    wlan_bonjour:
      additionalProperties: false
      description: Bonjour gateway wlan settings
      properties:
        additional_vlan_ids:
          $ref: '#/components/schemas/additional_vlan_ids'
        enabled:
          default: false
          description: Whether to enable bonjour for this WLAN. Once enabled, limit_bcast is assumed true, allow_mdns is assumed false
          type: boolean
        services:
          additionalProperties:
            $ref: '#/components/schemas/wlan_bonjour_service_properties'
          description: "What services are allowed. \nProperty key is the service name"
          examples:
          - airplay:
              radius_groups:
              - teachers
              scope: same_ap
          type: object
      type: object
    wlan_portal_sponsors:
      description: Object of allowed sponsors email with name. Required if `sponsor_enabled` is `true` and `sponsor_email_domains` is empty. Property key is the sponsor email, Property value is the sponsor name. List of email allowed for backward compatibility
      oneOf:
      - $ref: '#/components/schemas/wlan_portal_sponsors_list'
      - $ref: '#/components/schemas/wlan_portal_sponsors_object'
    hour:
      default: ''
      description: Hour range of the day (e.g. `09:00-17:00`). If the hour is not defined then it's treated as 00:00-23:59.
      examples:
      - 09:00-17:00
      type: string
    wlan_schedule:
      additionalProperties: false
      description: WLAN operating schedule, default is disabled
      properties:
        enabled:
          default: false
          type: boolean
        hours:
          $ref: '#/components/schemas/hours'
      type: object
    radsec_idle_timeout:
      anyOf:
      - default: 60
        type: integer
      - type: string
      description: Radsec Idle Timeout in seconds. Default is 60
    radius_acct_port:
      anyOf:
      - maximum: 65545
        minimum: 1
        type: integer
      - type: string
      description: Radius Auth Port, value from 1 to 65535, default is 1813
    wlan_bonjour_service_properties_scope:
      default: same_site
      description: 'how bonjour services should be discovered for the same WLAN. enum: `same_ap`, `same_map`, `same_site`'
      enum:
      - same_ap
      - same_map
      - same_site
      type: string
    wlan_bonjour_service_properties:
      additionalProperties: false
      properties:
        disable_local:
          default: false
          description: Whether to prevent wireless clients to discover bonjour devices on the same WLAN
          type: boolean
        radius_groups:
          $ref: '#/components/schemas/wlan_bonjour_service_properties_radius_groups'
        scope:
          $ref: '#/components/schemas/wlan_bonjour_service_properties_scope'
      type: object
    wlan_dynamic_vlan_default_vlan_ids:
      description: Default VLAN ID(s) can be a number, a range of VLAN IDs, a variable or multiple numbers, ranges or variables as a VLAN pool. Default VLAN as a pool of VLANS requires 0.14.x or newer firmware
      items:
        $ref: '#/components/schemas/wlan_dynamic_vlan_default_vlan_id'
      type: array
    secpolicy_list:
      items:
        $ref: '#/components/schemas/secpolicy'
      type: array
    radius_coa_port:
      anyOf:
      - maximum: 65545
        minimum: 1
        type: integer
      - type: string
      description: Radius CoA Port, value from 1 to 65535, default is 3799
    wlan_portal_allowed_subnets:
      default: []
      description: List of CIDRs
      examples:
      - - 63.5.3.0/24
      items:
        type: string
      type: array
    wlan_portal:
      additionalProperties: false
      description: Portal wlan settings
      properties:
        allow_wlan_id_roam:
          default: false
          description: Optional if `amazon_enabled`==`true`. Whether to allow guest to connect to other Guest WLANs (with different `WLAN.ssid`) of same org without reauthentication (disable random_mac for seamless roaming)
          type: boolean
        amazon_client_id:
          default: ''
          description: Optional if `amazon_enabled`==`true`. Amazon OAuth2 client id. This is optional. If not provided, it will use a default one.
          type:
          - string
          - 'null'
        amazon_client_secret:
          default: ''
          description: Optional if `amazon_enabled`==`true`. Amazon OAuth2 client secret. If amazon_client_id was provided, provide a corresponding value. Else leave blank.
          type:
          - string
          - 'null'
        amazon_email_domains:
          $ref: '#/components/schemas/wlan_portal_amazon_email_domains'
        amazon_enabled:
          default: false
          description: Whether amazon is enabled as a login method
          type: boolean
        amazon_expire:
          default: null
          description: Optional if `amazon_enabled`==`true`. Interval for which guest remains authorized using amazon auth (in minutes), if not provided, uses expire`
          type:
          - integer
          - 'null'
        auth:
          $ref: '#/components/schemas/wlan_portal_auth'
        azure_client_id:
          default: ''
          description: Required if `azure_enabled`==`true`. Azure active directory app client id
          type:
          - string
          - 'null'
        azure_client_secret:
          default: ''
          description: Required if `azure_enabled`==`true`. Azure active directory app client secret
          type:
          - string
          - 'null'
        azure_enabled:
          default: false
          description: Whether Azure Active Directory is enabled as a login method
          type: boolean
        azure_expire:
          default: null
          description: Interval for which guest remains authorized using azure auth (in minutes), if not provided, uses expire`
          type:
          - integer
          - 'null'
        azure_tenant_id:
          default: ''
          description: Required if `azure_enabled`==`true`. Azure active directory tenant id.
          type:
          - string
          - 'null'
        broadnet_password:
          default: ''
          description: Required if `sms_provider`==`broadnet`
          examples:
          - password
          format: password
          type: string
        broadnet_sid:
          description: Required if `sms_provider`==`broadnet`
          examples:
          - MIST
          type: string
        broadnet_user_id:
          description: Required if `sms_provider`==`broadnet`
          examples:
          - juniper
          type: string
        bypass_when_cloud_down:
          default: false
          description: Whether to bypass the guest portal when cloud not reachable (and apply the default policies)
          type: boolean
        clickatell_api_key:
          description: Required if `sms_provider`==`clickatell`
          type: string
        cross_site:
          default: false
          description: Whether to allow guest to roam between WLANs (with same `WLAN.ssid`, regardless of variables) of different sites of same org without reauthentication (disable random_mac for seamless roaming)
          type: boolean
        email_enabled:
          default: false
          description: Whether email (access code verification) is enabled as a login method
          type: boolean
        enabled:
          default: false
          description: Whether guest portal is enabled
          type: boolean
        expire:
          default: 1440
          description: How long to remain authorized, in minutes
          examples:
          - 1440
          type: integer
        external_portal_url:
          default: ''
          description: Required if `wlan_portal_auth`==`external`. External portal URL (e.g. https://host/url) where we can append our query parameters to
          type: string
        facebook_client_id:
          default: ''
          description: Required if `facebook_enabled`==`true`. Facebook OAuth2 app id. This is optional. If not provided, it will use a default one.
          type:
          - string
          - 'null'
        facebook_client_secret:
          default: ''
          description: Required if `facebook_enabled`==`true`. Facebook OAuth2 app secret. If facebook_client_id was provided, provide a corresponding value. Else leave blank.
          type:
          - string
          - 'null'
        facebook_email_domains:
          $ref: '#/components/schemas/wlan_portal_facebook_email_domains'
        facebook_enabled:
          default: false
          description: Whether facebook is enabled as a login method
          type: boolean
        facebook_expire:
          default: null
          description: Optional if `facebook_enabled`==`true`. Interval for which guest remains authorized using facebook auth (in minutes), if not provided, uses expire`
          type:
          - integer
          - 'null'
        forward:
          default: false
          description: Whether to forward the user to another URL after authorized
          type: boolean
        forward_url:
          default: ''
          description: URL to forward the user to
          examples:
          - https://abc.com/promotions
          type:
          - string
          - 'null'
        google_client_id:
          default: ''
          description: Google OAuth2 app id. This is optional. If not provided, it will use a default one.
          type:
          - string
          - 'null'
        google_client_secret:
          default: ''
          description: Optional if `google_enabled`==`true`. Google OAuth2 app secret. If google_client_id was provided, provide a corresponding value. Else leave blank.
          type:
          - string
          - 'null'
        google_email_domains:
          $ref: '#/components/schemas/wlan_portal_google_email_domains'
        google_enabled:
          default: false
          description: Whether Google is enabled as login method
          type: boolean
        google_expire:
          default: null
          description: Optional if `google_enabled`==`true`. Interval for which guest remains authorized using Google Auth (in minutes), if not provided, uses expire`
          type:
          - integer
          - 'null'
        gupshup_password:
          description: Required if `sms_provider`==`gupshup`
          format: password
          type: string
        gupshup_userid:
          description: Required if `sms_provider`==`gupshup`
          type: string
        microsoft_client_id:
          default: ''
          description: Optional if `microsoft_enabled`==`true`. Microsoft 365 OAuth2 client id. This is optional. If not provided, it will use a default one.
          type:
          - string
          - 'null'
        microsoft_client_secret:
          default: ''
          description: Optional if `microsoft_enabled`==`true`. Microsoft 365 OAuth2 client secret. If microsoft_client_id was provided, provide a corresponding value. Else leave blank.
          type:
          - string
          - 'null'
        microsoft_email_domains:
          $ref: '#/components/schemas/wlan_portal_microsoft_email_domains'
        microsoft_enabled:
          default: false
          description: Whether microsoft 365 is enabled as a login method
          type: boolean
        microsoft_expire:
          default: null
          description: Optional if `microsoft_enabled`==`true`. Interval for which guest remains authorized using microsoft auth (in minutes), if not provided, uses expire`
          type:
          - integer
          - 'null'
        passphrase_enabled:
          default: false
          description: Whether password is enabled
          type: boolean
        passphrase_expire:
          default: null
          description: Optional if `passphrase_enabled`==`true`. Interval for which guest remains authorized using passphrase auth (in minutes), if not provided, uses `expire`
          type:
          - integer
          - 'null'
        password:
          default: ''
          description: Required if `passphrase_enabled`==`true`.
          examples:
          - let me in
          type:
          - string
          - 'null'
        predefined_sponsors_enabled:
          default: true
          description: Whether to show list of sponsor emails mentioned in `sponsors` object as a dropdown. If both `sponsor_notify_all` and `predefined_sponsors_enabled` are false, behavior is acc to `sponsor_email_domains`
          type: boolean
        predefined_sponsors_hide_email:
          default: false
          description: Whether to hide sponsor’s email from list of sponsors
          type: boolean
        privacy:
          default: false
          type: boolean
  

# --- truncated at 32 KB (95 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/mist-ai/refs/heads/main/openapi/mist-ai-orgs-security-policies-api-openapi.yml