Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Identity.SignIns Identity Protection.risky User API

16 actions 16 updates phrasing extends openapi/azure-ad-identityprotection-riskyuser-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 16

$.info
$.paths['/identityProtection/riskyUsers'].get
$.paths['/identityProtection/riskyUsers'].post
$.paths['/identityProtection/riskyUsers/{riskyUser-id}'].get
$.paths['/identityProtection/riskyUsers/{riskyUser-id}'].delete
$.paths['/identityProtection/riskyUsers/{riskyUser-id}'].patch
$.paths['/identityProtection/riskyUsers/{riskyUser-id}/history'].get
$.paths['/identityProtection/riskyUsers/{riskyUser-id}/history'].post
$.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}'].get
$.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}'].delete
$.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}'].patch
$.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/$count'].get
$.paths['/identityProtection/riskyUsers/$count'].get
$.paths['/identityProtection/riskyUsers/microsoft.graph.confirmCompromised'].post
$.paths['/identityProtection/riskyUsers/microsoft.graph.confirmSafe'].post
$.paths['/identityProtection/riskyUsers/microsoft.graph.dismiss'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Identity.SignIns Identity Protection.risky User API
  version: 1.0.0
extends: openapi/azure-ad-identityprotection-riskyuser-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 15
- target: $.paths['/identityProtection/riskyUsers'].get
  update:
    x-apievangelist-phrasing:
      intent: List users flagged as risky
      effect: read
      questions:
      - Which users in my tenant has Identity Protection flagged as risky?
      - Can I filter risky users down to only those at high risk level?
      - How do I pull the full list of risky users with their risk state?
      instructions:
      - text: List all risky users in my tenant.
      - text: Show risky users matching filter {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a risky user record
      effect: write
      questions:
      - Can I add a new riskyUser entry to Identity Protection myself?
      - What fields like risk level and risk state can I set when creating a risky user record?
      instructions:
      - text: Create a risky user record for {upn} with risk level {level}.
        slots:
          upn: requestBody.userPrincipalName
          level: requestBody.riskLevel
      - text: Add a new riskyUser entry for {upn} in risk state {state}.
        slots:
          upn: requestBody.userPrincipalName
          state: requestBody.riskState
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one risky user's risk details
      effect: read
      questions:
      - What is a specific user's current risk level and why were they flagged?
      - When was a particular risky user's risk last updated?
      instructions:
      - text: Get the risk details for risky user {user}.
        slots:
          user: path.riskyUser-id
      - text: Show the risk level and risk state of user {user}.
        slots:
          user: path.riskyUser-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a risky user record
      effect: destructive
      questions:
      - Can I remove a user's riskyUser record from Identity Protection entirely?
      - What's the call to delete a single risky user entry by ID?
      instructions:
      - text: Delete the risky user record {user}.
        slots:
          user: path.riskyUser-id
      - text: Remove riskyUser entry {user} from Identity Protection.
        slots:
          user: path.riskyUser-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a risky user record's properties
      effect: write
      questions:
      - Can I edit the properties on an existing risky user record directly?
      - Which riskyUser fields, like risk detail or display name, can I patch?
      instructions:
      - text: Update risky user {user} to risk level {level}.
        slots:
          user: path.riskyUser-id
          level: requestBody.riskLevel
      - text: Patch the risk state of riskyUser record {user} to {state}.
        slots:
          user: path.riskyUser-id
          state: requestBody.riskState
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}/history'].get
  update:
    x-apievangelist-phrasing:
      intent: List a risky user's risk history
      effect: read
      questions:
      - How has a user's risk level changed over time?
      - What risk-change activity has been recorded for one risky user?
      instructions:
      - text: List the risk history for risky user {user}.
        slots:
          user: path.riskyUser-id
      - text: Show every risk-level change recorded for user {user}.
        slots:
          user: path.riskyUser-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}/history'].post
  update:
    x-apievangelist-phrasing:
      intent: Add an entry to a risky user's history
      effect: write
      questions:
      - Can I append a history item to a risky user's record?
      - What does a risky user history entry store, such as who initiated it?
      instructions:
      - text: Add a history entry to risky user {user} initiated by {initiator}.
        slots:
          user: path.riskyUser-id
          initiator: requestBody.initiatedBy
      - text: Record activity {activity} in the risk history of user {user}.
        slots:
          user: path.riskyUser-id
          activity: requestBody.activity
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one entry from a risky user's history
      effect: read
      questions:
      - What happened in one specific risk-change event for a user?
      - Can I look up a single risky user history item by its ID?
      instructions:
      - text: Get history item {item} for risky user {user}.
        slots:
          user: path.riskyUser-id
          item: path.riskyUserHistoryItem-id
      - text: Show the risk-change activity in entry {item} of user {user}'s history.
        slots:
          user: path.riskyUser-id
          item: path.riskyUserHistoryItem-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an entry from a risky user's history
      effect: destructive
      questions:
      - Can I remove a single item from a risky user's history?
      - Is it possible to delete one risk-change record while keeping the rest of the history?
      instructions:
      - text: Delete history item {item} from risky user {user}.
        slots:
          user: path.riskyUser-id
          item: path.riskyUserHistoryItem-id
      - text: Remove entry {item} from user {user}'s risk history.
        slots:
          user: path.riskyUser-id
          item: path.riskyUserHistoryItem-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update an entry in a risky user's history
      effect: write
      questions:
      - Can I edit an existing item in a risky user's history?
      - Which fields of a risk history entry, like its activity, are editable?
      instructions:
      - text: Update history item {item} of risky user {user} with activity {activity}.
        slots:
          user: path.riskyUser-id
          item: path.riskyUserHistoryItem-id
          activity: requestBody.activity
      - text: Change who initiated entry {item} in user {user}'s risk history to {initiator}.
        slots:
          user: path.riskyUser-id
          item: path.riskyUserHistoryItem-id
          initiator: requestBody.initiatedBy
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/{riskyUser-id}/history/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count a risky user's history entries
      effect: read
      questions:
      - How many risk-change events have been logged for one user?
      - Can I get just the number of history items on a risky user?
      instructions:
      - text: Count the history entries for risky user {user}.
        slots:
          user: path.riskyUser-id
      - text: Tell me how many risk-change records user {user} has.
        slots:
          user: path.riskyUser-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count risky users in the tenant
      effect: read
      questions:
      - How many users are currently flagged as risky in my tenant?
      - Can I get a count of risky users without listing them all?
      instructions:
      - text: Count the risky users in my tenant.
      - text: Tell me how many risky users match filter {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/microsoft.graph.confirmCompromised'].post
  update:
    x-apievangelist-phrasing:
      intent: Confirm risky users as compromised
      effect: write
      questions:
      - How do I mark a user as confirmed compromised so their risk goes to high?
      - Can I confirm several risky users as compromised in one call?
      instructions:
      - text: Confirm users {user_ids} as compromised.
        slots:
          user_ids: requestBody.userIds
      - text: 'Mark these accounts as compromised and raise their risk to high: {user_ids}.'
        slots:
          user_ids: requestBody.userIds
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/microsoft.graph.confirmSafe'].post
  update:
    x-apievangelist-phrasing:
      intent: Confirm risky users as safe
      effect: write
      questions:
      - What's the way to tell Identity Protection a flagged user was a false positive and is actually safe?
      - Does confirming a user safe reset their risk level to none?
      instructions:
      - text: Confirm users {user_ids} as safe.
        slots:
          user_ids: requestBody.userIds
      - text: 'Mark these flagged accounts as confirmed safe: {user_ids}.'
        slots:
          user_ids: requestBody.userIds
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/riskyUsers/microsoft.graph.dismiss'].post
  update:
    x-apievangelist-phrasing:
      intent: Dismiss risk on risky users
      effect: write
      questions:
      - Can I dismiss the risk on a batch of users without confirming them safe or compromised?
      - What happens to a user's risk level when I dismiss it?
      instructions:
      - text: Dismiss the risk for users {user_ids}.
        slots:
          user_ids: requestBody.userIds
      - text: 'Clear the user risk on these accounts by dismissing it: {user_ids}.'
        slots:
          user_ids: requestBody.userIds
      method: generated
      generated: '2026-10-01'