Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Applications.application.Actions API

15 actions 15 updates phrasing extends openapi/azure-ad-applications-application-actions-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 15

$.info
$.paths['/applications/{application-id}/microsoft.graph.addKey'].post
$.paths['/applications/{application-id}/microsoft.graph.addPassword'].post
$.paths['/applications/{application-id}/microsoft.graph.checkMemberGroups'].post
$.paths['/applications/{application-id}/microsoft.graph.checkMemberObjects'].post
$.paths['/applications/{application-id}/microsoft.graph.getMemberGroups'].post
$.paths['/applications/{application-id}/microsoft.graph.getMemberObjects'].post
$.paths['/applications/{application-id}/microsoft.graph.removeKey'].post
$.paths['/applications/{application-id}/microsoft.graph.removePassword'].post
$.paths['/applications/{application-id}/microsoft.graph.restore'].post
$.paths['/applications/{application-id}/microsoft.graph.setVerifiedPublisher'].post
$.paths['/applications/{application-id}/microsoft.graph.unsetVerifiedPublisher'].post
$.paths['/applications/microsoft.graph.getAvailableExtensionProperties'].post
$.paths['/applications/microsoft.graph.getByIds'].post
$.paths['/applications/microsoft.graph.validateProperties'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Applications.application.Actions API
  version: 1.0.0
extends: openapi/azure-ad-applications-application-actions-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 14
- target: $.paths['/applications/{application-id}/microsoft.graph.addKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a certificate key credential to an app
      effect: write
      questions:
      - How do I roll an expiring certificate on an app registration automatically?
      - Can I add a new key credential to an app with a signed proof of possession?
      instructions:
      - text: Add key credential {key} to application {app_id} using proof {proof}.
        slots:
          app_id: path.application-id
          key: requestBody.keyCredential
          proof: requestBody.proof
      - text: Upload a new certificate key to app registration {app_id}.
        slots:
          app_id: path.application-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.addPassword'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a client secret to an app
      effect: write
      questions:
      - How do I generate a new client secret for my app registration?
      - Can I give a new application password a display name and end date?
      instructions:
      - text: Create a new client secret on application {app_id}.
        slots:
          app_id: path.application-id
      - text: Add password credential {password} to app {app_id}.
        slots:
          app_id: path.application-id
          password: requestBody.passwordCredential
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.checkMemberGroups'].post
  update:
    x-apievangelist-phrasing:
      intent: Check an app's membership in given groups
      effect: read
      questions:
      - Which of a list of groups does an application object belong to?
      - Can I test an app registration against specific group IDs?
      instructions:
      - text: Check whether application {app_id} is in any of the groups {group_ids}.
        slots:
          app_id: path.application-id
          group_ids: requestBody.groupIds
      - text: Tell me which of {group_ids} contain app {app_id}.
        slots:
          app_id: path.application-id
          group_ids: requestBody.groupIds
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.checkMemberObjects'].post
  update:
    x-apievangelist-phrasing:
      intent: Check an app against directory object IDs
      effect: read
      questions:
      - Is an app a member of certain groups, admin units or roles by ID?
      - Can I check an application's memberships against a mixed list of object IDs?
      instructions:
      - text: Check application {app_id} for membership in objects {ids}.
        slots:
          app_id: path.application-id
          ids: requestBody.ids
      - text: Run checkMemberObjects for app registration {app_id}.
        slots:
          app_id: path.application-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.getMemberGroups'].post
  update:
    x-apievangelist-phrasing:
      intent: List all groups an app belongs to
      effect: read
      questions:
      - What groups is an app registration a member of?
      - Can I return only the security groups an application is in?
      instructions:
      - text: Get every group ID that application {app_id} belongs to.
        slots:
          app_id: path.application-id
      - text: List groups for app {app_id} with security-enabled only {security_only}.
        slots:
          app_id: path.application-id
          security_only: requestBody.securityEnabledOnly
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.getMemberObjects'].post
  update:
    x-apievangelist-phrasing:
      intent: List groups, admin units and roles of an app
      effect: read
      questions:
      - Which groups, administrative units and directory roles include this application?
      - Can I get an app's full membership list, not just groups?
      instructions:
      - text: Get member objects of application {app_id}, including admin units and roles.
        slots:
          app_id: path.application-id
      - text: List all memberships of app {app_id} with security-enabled only {security_only}.
        slots:
          app_id: path.application-id
          security_only: requestBody.securityEnabledOnly
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.removeKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a certificate key credential from an app
      effect: destructive
      questions:
      - How do I retire an old certificate from an app registration after rolling it?
      - Does removing an app key need a proof-of-possession token?
      instructions:
      - text: Remove key {key_id} from application {app_id} with proof {proof}.
        slots:
          app_id: path.application-id
          key_id: requestBody.keyId
          proof: requestBody.proof
      - text: Delete the certificate credential {key_id} on app {app_id}.
        slots:
          app_id: path.application-id
          key_id: requestBody.keyId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.removePassword'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a client secret from an app
      effect: destructive
      questions:
      - How do I revoke a leaked client secret on my app registration?
      - Can I delete one application password by its key ID?
      instructions:
      - text: Remove client secret {key_id} from application {app_id}.
        slots:
          app_id: path.application-id
          key_id: requestBody.keyId
      - text: Revoke password credential {key_id} on app {app_id}.
        slots:
          app_id: path.application-id
          key_id: requestBody.keyId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.restore'].post
  update:
    x-apievangelist-phrasing:
      intent: Restore a deleted app registration
      effect: write
      questions:
      - How do I bring back an app registration someone deleted?
      - Can I undelete an application by its object ID?
      instructions:
      - text: Restore application {app_id} from deleted items.
        slots:
          app_id: path.application-id
      - text: Undelete app registration {app_id}.
        slots:
          app_id: path.application-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.setVerifiedPublisher'].post
  update:
    x-apievangelist-phrasing:
      intent: Set the verified publisher on an app
      effect: write
      questions:
      - How do I get the blue verified badge on my app's consent prompt?
      - Can I link my app registration to a Partner Center publisher ID?
      instructions:
      - text: Set verified publisher {publisher_id} on application {app_id}.
        slots:
          app_id: path.application-id
          publisher_id: requestBody.verifiedPublisherId
      - text: Mark app {app_id} as published by verified publisher {publisher_id}.
        slots:
          app_id: path.application-id
          publisher_id: requestBody.verifiedPublisherId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/{application-id}/microsoft.graph.unsetVerifiedPublisher'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove the verified publisher from an app
      effect: destructive
      questions:
      - How do I take the verified publisher off an app registration?
      - What happens to the publisher properties when I unset verification on an app?
      instructions:
      - text: Unset the verified publisher on application {app_id}.
        slots:
          app_id: path.application-id
      - text: Clear all verified publisher properties from app {app_id}.
        slots:
          app_id: path.application-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/microsoft.graph.getAvailableExtensionProperties'].post
  update:
    x-apievangelist-phrasing:
      intent: List registered directory extension properties
      effect: read
      questions:
      - What directory extension attributes are registered in my tenant, including by multitenant apps?
      - Can I list only the extension properties synced from on-premises?
      instructions:
      - text: List all available directory extension properties.
      - text: Get extension definitions where synced from on-premises is {synced}.
        slots:
          synced: requestBody.isSyncedFromOnPremises
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/microsoft.graph.getByIds'].post
  update:
    x-apievangelist-phrasing:
      intent: Fetch directory objects by a list of IDs
      effect: read
      questions:
      - How can I resolve a batch of object IDs to apps, users or groups in one request?
      - Can I restrict an ID lookup to application objects only?
      instructions:
      - text: Look up the directory objects with IDs {ids}.
        slots:
          ids: requestBody.ids
      - text: Resolve IDs {ids} returning only types {types}.
        slots:
          ids: requestBody.ids
          types: requestBody.types
      method: generated
      generated: '2026-10-01'
- target: $.paths['/applications/microsoft.graph.validateProperties'].post
  update:
    x-apievangelist-phrasing:
      intent: Check a group name against naming policy
      effect: read
      questions:
      - Will a Microsoft 365 group display name pass my tenant's naming policy?
      - Can I check a mail nickname for blocked words before creating the group?
      instructions:
      - text: Validate display name {display_name} and mail nickname {nickname}.
        slots:
          display_name: requestBody.displayName
          nickname: requestBody.mailNickname
      - text: Check {display_name} against naming policy on behalf of user {user_id}.
        slots:
          display_name: requestBody.displayName
          user_id: requestBody.onBehalfOfUserId
      method: generated
      generated: '2026-10-01'