Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Identity.Governance Identity Governance.privileged Access…
93 actions
93 updates
phrasing
extends
openapi/azure-ad-identitygovernance-privilegedaccessroot-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
What the actions change
x-apievangelist-phrasing
Targets 93 · first 16 shown; the file carries all of them
$.info
$.paths['/identityGovernance/privilegedAccess'].get
$.paths['/identityGovernance/privilegedAccess'].delete
$.paths['/identityGovernance/privilegedAccess'].patch
$.paths['/identityGovernance/privilegedAccess/group'].get
$.paths['/identityGovernance/privilegedAccess/group'].delete
$.paths['/identityGovernance/privilegedAccess/group'].patch
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals'].get
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals'].post
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}'].get
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}'].delete
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}'].patch
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages'].get
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages'].post
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages/{approvalStage-id}'].get
$.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages/{approvalStage-id}'].delete
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Identity.Governance Identity Governance.privileged Access…
version: 1.0.0
extends: openapi/azure-ad-identitygovernance-privilegedaccessroot-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 92
- target: $.paths['/identityGovernance/privilegedAccess'].get
update:
x-apievangelist-phrasing:
intent: Get the privileged access root
effect: read
questions:
- What does the privileged access root in identity governance expose?
- Is PIM for Groups reachable under the privileged access object?
instructions:
- text: Show the privileged access root for identity governance.
- text: Fetch privileged access, expanding {expand}.
slots:
expand: query.$expand
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess'].delete
update:
x-apievangelist-phrasing:
intent: Delete the privileged access root
effect: destructive
questions:
- Can I remove the privilegedAccess navigation property from identity governance?
- Is it possible to delete the whole privileged access container?
instructions:
- text: Delete the privileged access root from identity governance.
- text: Remove privileged access only if its ETag still matches {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess'].patch
update:
x-apievangelist-phrasing:
intent: Update the privileged access root
effect: write
questions:
- Can I patch the privileged access root object?
- What can I change on the top-level privileged access object?
instructions:
- text: 'Update the privileged access root with this group payload: {group}.'
slots:
group: requestBody.group
- text: Patch the privileged access root in identity governance.
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group'].get
update:
x-apievangelist-phrasing:
intent: Get the PIM for Groups container
effect: read
questions:
- Where do I find the groups governed by Privileged Identity Management?
- What PIM for Groups data sits under privileged access?
instructions:
- text: Show the PIM for Groups container under privileged access.
- text: Get the PIM group container and expand {expand}.
slots:
expand: query.$expand
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group'].delete
update:
x-apievangelist-phrasing:
intent: Delete the PIM for Groups container
effect: destructive
questions:
- Can I delete the PIM for Groups navigation property?
- Is there a way to clear the governed-group container under privileged access?
instructions:
- text: Delete the PIM for Groups container.
- text: Delete the PIM group container if it matches ETag {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group'].patch
update:
x-apievangelist-phrasing:
intent: Update the PIM for Groups container
effect: write
questions:
- Can I patch the PIM for Groups container in one request?
- Which collections can I set when updating the PIM group container?
instructions:
- text: 'Update the PIM for Groups container with these eligibility schedules: {schedules}.'
slots:
schedules: requestBody.eligibilitySchedules
- text: Replace the container's assignment schedules with {schedules}.
slots:
schedules: requestBody.assignmentSchedules
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals'].get
update:
x-apievangelist-phrasing:
intent: List PIM group assignment approvals
effect: read
questions:
- Which approvals exist for PIM group assignment requests?
- Can I page through group assignment approvals with top and skip?
instructions:
- text: List all PIM group assignment approvals.
- text: List group assignment approvals matching {filter}.
slots:
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals'].post
update:
x-apievangelist-phrasing:
intent: Create a PIM group assignment approval
effect: write
questions:
- Can I create a new approval object for PIM group assignments?
- What fields does a new group assignment approval take?
instructions:
- text: Create a PIM group assignment approval with stages {stages}.
slots:
stages: requestBody.stages
- text: Add a new assignment approval under PIM for Groups.
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}'].get
update:
x-apievangelist-phrasing:
intent: Get a PIM group assignment approval
effect: read
questions:
- How do I look up a single PIM group assignment approval by ID?
- Can I read one assignment approval and choose which properties come back?
instructions:
- text: Get PIM group assignment approval {approval}.
slots:
approval: path.approval-id
- text: Show approval {approval} with only {select}.
slots:
approval: path.approval-id
select: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a PIM group assignment approval
effect: destructive
questions:
- Can I delete a PIM group assignment approval?
- Is an ETag needed to remove a specific assignment approval?
instructions:
- text: Delete assignment approval {approval}.
slots:
approval: path.approval-id
- text: Remove group assignment approval {approval} if ETag {etag} matches.
slots:
approval: path.approval-id
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}'].patch
update:
x-apievangelist-phrasing:
intent: Update a PIM group assignment approval
effect: write
questions:
- Can I change the stages on an existing group assignment approval?
- Is patching a PIM assignment approval I already have supported?
instructions:
- text: Update the stages of assignment approval {approval} to {stages}.
slots:
approval: path.approval-id
stages: requestBody.stages
- text: Patch PIM group assignment approval {approval}.
slots:
approval: path.approval-id
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages'].get
update:
x-apievangelist-phrasing:
intent: List stages of an assignment approval
effect: read
questions:
- What stages does a PIM group assignment approval go through?
- Can I filter an approval's stages by status?
instructions:
- text: List the stages of approval {approval}.
slots:
approval: path.approval-id
- text: Show stages of approval {approval} matching {filter}.
slots:
approval: path.approval-id
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages'].post
update:
x-apievangelist-phrasing:
intent: Add a stage to an assignment approval
effect: write
questions:
- Can I add a stage to a PIM group assignment approval?
- What can I set on a new approval stage, like justification or reviewer?
instructions:
- text: Add a stage named {name} to approval {approval}.
slots:
name: requestBody.displayName
approval: path.approval-id
- text: Create a stage on approval {approval} with justification {justification}.
slots:
approval: path.approval-id
justification: requestBody.justification
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages/{approvalStage-id}'].get
update:
x-apievangelist-phrasing:
intent: Get one stage of an assignment approval
effect: read
questions:
- How do I read one stage of an assignment approval?
- Who reviewed a particular approval stage and when?
instructions:
- text: Get stage {stage} of approval {approval}.
slots:
stage: path.approvalStage-id
approval: path.approval-id
- text: Show the review result of stage {stage} in approval {approval}, selecting {select}.
slots:
stage: path.approvalStage-id
approval: path.approval-id
select: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages/{approvalStage-id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a stage from an assignment approval
effect: destructive
questions:
- Can I delete a stage from an assignment approval?
- Is it possible to remove one approval stage by its ID?
instructions:
- text: Delete stage {stage} from approval {approval}.
slots:
stage: path.approvalStage-id
approval: path.approval-id
- text: Remove approval stage {stage} on {approval} if ETag {etag} matches.
slots:
stage: path.approvalStage-id
approval: path.approval-id
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages/{approvalStage-id}'].patch
update:
x-apievangelist-phrasing:
intent: Review a stage of an assignment approval
effect: write
questions:
- How do I approve or deny a stage of a PIM group assignment approval?
- Can I add my justification when reviewing an approval stage?
instructions:
- text: Set the review result of stage {stage} on approval {approval} to {result}.
slots:
stage: path.approvalStage-id
approval: path.approval-id
result: requestBody.reviewResult
- text: Update stage {stage} of approval {approval} with justification {justification}.
slots:
stage: path.approvalStage-id
approval: path.approval-id
justification: requestBody.justification
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/{approval-id}/stages/$count'].get
update:
x-apievangelist-phrasing:
intent: Count stages of an assignment approval
effect: read
questions:
- How many stages does a given assignment approval have?
- Can I count an approval's stages that match a filter?
instructions:
- text: Count the stages on approval {approval}.
slots:
approval: path.approval-id
- text: Count stages of approval {approval} matching {filter}.
slots:
approval: path.approval-id
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/$count'].get
update:
x-apievangelist-phrasing:
intent: Count PIM group assignment approvals
effect: read
questions:
- How many PIM group assignment approvals are there?
- Can I get just the total of assignment approvals without the records?
instructions:
- text: Count all PIM group assignment approvals.
- text: Count assignment approvals where {filter}.
slots:
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentApprovals/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get
update:
x-apievangelist-phrasing:
intent: List my assignment approvals
effect: read
questions:
- Which PIM group assignment approvals are waiting on me?
- Can I see only the approvals that are in scope for me as a reviewer?
instructions:
- text: List the assignment approvals in scope for me as {on}.
slots:
'on': path.on
- text: Show my group assignment approvals as {on}, top {top}.
slots:
'on': path.on
top: query.$top
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances'].get
update:
x-apievangelist-phrasing:
intent: List active PIM group assignment instances
effect: read
questions:
- Who currently has active membership or ownership through PIM for Groups?
- Can I filter active group assignment instances by group?
instructions:
- text: List all active PIM group assignment instances.
- text: List active assignment instances where {filter}.
slots:
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances'].post
update:
x-apievangelist-phrasing:
intent: Create an active assignment instance
effect: write
questions:
- Can I create an assignment schedule instance record directly?
- What fields go into a new active assignment instance, like memberType?
instructions:
- text: Create an active assignment instance for principal {principal} in group {group}.
slots:
principal: requestBody.principalId
group: requestBody.groupId
- text: Add an assignment instance with access {access} for group {group}.
slots:
access: requestBody.accessId
group: requestBody.groupId
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}'].get
update:
x-apievangelist-phrasing:
intent: Get an active assignment instance
effect: read
questions:
- How do I read one active group assignment instance?
- Which properties can I select on a single active assignment instance?
instructions:
- text: Get active assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Show assignment instance {instance} selecting {select}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
select: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an active assignment instance
effect: destructive
questions:
- Can I delete an active assignment instance object?
- Does removing an assignment instance record need an ETag?
instructions:
- text: Delete active assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Remove assignment instance {instance} if ETag {etag} matches.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}'].patch
update:
x-apievangelist-phrasing:
intent: Update an active assignment instance
effect: write
questions:
- Can I change the member type on an existing active assignment instance?
- Is patching an active assignment instance supported?
instructions:
- text: Update assignment instance {instance} to member type {memberType}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
memberType: requestBody.memberType
- text: Patch active assignment instance {instance} with group {group}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
group: requestBody.groupId
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}/activatedUsing'].get
update:
x-apievangelist-phrasing:
intent: Get the eligibility behind an active instance
effect: read
questions:
- Which eligibility was used to activate this active assignment instance?
- Was an active assignment instance activated from an eligible schedule?
instructions:
- text: Show the eligibility that activated assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Get activatedUsing for active instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}/group'].get
update:
x-apievangelist-phrasing:
intent: Get the group of an active assignment instance
effect: read
questions:
- Which group does an active assignment instance grant access to?
- Can I see the group behind a given active assignment instance?
instructions:
- text: Get the group for active assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Get {select} from the group behind active instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
select: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}/group/serviceProvisioningErrors'].get
update:
x-apievangelist-phrasing:
intent: List group errors for an active instance
effect: read
questions:
- Are there provisioning errors on the group of an active assignment instance?
- Can I list service provisioning errors for the group behind an assignment instance?
instructions:
- text: List provisioning errors on the group of assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Show group provisioning errors for active instance {instance} matching {filter}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}/group/serviceProvisioningErrors/$count'].get
update:
x-apievangelist-phrasing:
intent: Count group errors for an active instance
effect: read
questions:
- How many provisioning errors does the group of an active assignment instance have?
- Can I count group provisioning errors for one active assignment instance?
instructions:
- text: Count provisioning errors on the group behind assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Count group errors for active instance {instance} where {filter}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/{privilegedAccessGroupAssignmentScheduleInstance-id}/principal'].get
update:
x-apievangelist-phrasing:
intent: Get the principal of an active assignment
effect: read
questions:
- Who is the user or principal on an active assignment instance?
- Can I see which principal holds a specific active group assignment?
instructions:
- text: Get the principal of assignment instance {instance}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
- text: Show who holds active instance {instance}, selecting {select}.
slots:
instance: path.privilegedAccessGroupAssignmentScheduleInstance-id
select: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/$count'].get
update:
x-apievangelist-phrasing:
intent: Count active PIM group assignment instances
effect: read
questions:
- How many active PIM group assignment instances are there?
- Can I count active assignment instances matching a filter?
instructions:
- text: Count active PIM group assignment instances.
- text: Count active assignment instances where {filter}.
slots:
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleInstances/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get
update:
x-apievangelist-phrasing:
intent: List my active group assignments
effect: read
questions:
- Which PIM groups am I actively a member or owner of right now?
- Can I list only my own active assignment instances?
instructions:
- text: List my active group assignment instances as {on}.
slots:
'on': path.on
- text: Show my active assignment instances as {on}, ordered by {orderby}.
slots:
'on': path.on
orderby: query.$orderby
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests'].get
update:
x-apievangelist-phrasing:
intent: List PIM group assignment requests
effect: read
questions:
- What membership and ownership assignment requests have been made for PIM groups?
- Can I filter group assignment requests by principal?
instructions:
- text: List all PIM group assignment requests.
- text: List assignment requests matching {filter}, ordered by {orderby}.
slots:
filter: query.$filter
orderby: query.$orderby
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests'].post
update:
x-apievangelist-phrasing:
intent: Request a PIM group assignment
effect: write
questions:
- How do I request membership or ownership of a PIM-governed group?
- Can I assign a user as a group member through a PIM request?
instructions:
- text: Request a group assignment for principal {principal} in group {group} with access {access}.
slots:
principal: requestBody.principalId
group: requestBody.groupId
access: requestBody.accessId
- text: Submit an assignment request adding {principal} to group {group}.
slots:
principal: requestBody.principalId
group: requestBody.groupId
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}'].get
update:
x-apievangelist-phrasing:
intent: Get a PIM group assignment request
effect: read
questions:
- How do I check a single group assignment request?
- Which properties can I pull from one assignment request?
instructions:
- text: Get assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Show group assignment request {request} expanding {expand}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
expand: query.$expand
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a PIM group assignment request
effect: destructive
questions:
- Can I delete a group assignment request record?
- Does deleting an assignment request require an If-Match ETag?
instructions:
- text: Delete group assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Remove assignment request {request} when ETag is {etag}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}'].patch
update:
x-apievangelist-phrasing:
intent: Update a PIM group assignment request
effect: write
questions:
- Can I edit an assignment request after it was submitted?
- Is it possible to change the target schedule on an assignment request?
instructions:
- text: Update assignment request {request} to target schedule {schedule}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
schedule: requestBody.targetScheduleId
- text: Patch group assignment request {request} with principal {principal}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
principal: requestBody.principalId
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}/activatedUsing'].get
update:
x-apievangelist-phrasing:
intent: Get the eligibility behind an assignment request
effect: read
questions:
- Which eligibility policy did an assignment request activate against?
- Was this assignment request an activation of an eligible membership?
instructions:
- text: Show the eligibility behind assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Get activatedUsing for group assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}/group'].get
update:
x-apievangelist-phrasing:
intent: Get the group of an assignment request
effect: read
questions:
- Which group is an assignment request for?
- Can I see the target group of a pending assignment request?
instructions:
- text: Get the group targeted by assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Return just {select} for the group an assignment request {request} targets.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
select: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}/group/serviceProvisioningErrors'].get
update:
x-apievangelist-phrasing:
intent: List group errors for an assignment request
effect: read
questions:
- Does the group in an assignment request have provisioning errors?
- Can I list federated service errors for the group on an assignment request?
instructions:
- text: List provisioning errors for the group on assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Show errors on the requested group for {request}, top {top}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
top: query.$top
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}/group/serviceProvisioningErrors/$count'].get
update:
x-apievangelist-phrasing:
intent: Count group errors for an assignment request
effect: read
questions:
- How many provisioning errors are on the group of an assignment request?
- Can I count provisioning errors tied to an assignment request's group?
instructions:
- text: Count provisioning errors for the group on assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Count errors on the requested group of {request} matching {filter}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/identityGovernance/privilegedAccess/group/assignmentScheduleRequests/{privilegedAccessGroupAssignmentScheduleRequest-id}/microsoft.graph.cancel'].post
update:
x-apievangelist-phrasing:
intent: Cancel a PIM group assignment request
effect: destructive
questions:
- Can I cancel a pending PIM group assignment request?
- How do I withdraw a membership or ownership request I made?
instructions:
- text: Cancel group assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
- text: Withdraw PIM assignment request {request}.
slots:
request: path.privilegedAccessGroupAssignmentScheduleRequest-id
method: generated
generated: '2026-10-01'
# --- truncated at 32 KB (70 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/azure-ad/refs/heads/main/overlays/azure-ad-identitygovernance-privilegedaccessroot-api-phrasing-overlay.yaml