Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Identity.SignIns Identity Protection.service Principal Risk…

7 actions 7 updates phrasing extends openapi/azure-ad-identityprotection-serviceprincipalriskdetection-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 7

$.info
$.paths['/identityProtection/servicePrincipalRiskDetections'].get
$.paths['/identityProtection/servicePrincipalRiskDetections'].post
$.paths['/identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}'].get
$.paths['/identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}'].delete
$.paths['/identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}'].patch
$.paths['/identityProtection/servicePrincipalRiskDetections/$count'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Identity.SignIns Identity Protection.service Principal Risk…
  version: 1.0.0
extends: openapi/azure-ad-identityprotection-serviceprincipalriskdetection-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 6
- target: $.paths['/identityProtection/servicePrincipalRiskDetections'].get
  update:
    x-apievangelist-phrasing:
      intent: List service principal risk detections
      effect: read
      questions:
      - Which risky activities has Identity Protection detected for my apps' service principals?
      - Can I filter workload identity risk detections by risk level or state?
      instructions:
      - text: List all service principal risk detections in Identity Protection.
      - text: Show detected risks for workload identities, with risk level and IP address.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/servicePrincipalRiskDetections'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a service principal risk detection
      effect: write
      questions:
      - Can I record a new risk detection against a service principal?
      - Which fields, like risk level and event type, can a new service principal risk detection carry?
      instructions:
      - text: Create a risk detection for service principal {sp_id} with risk level {risk_level}.
        slots:
          sp_id: requestBody.servicePrincipalId
          risk_level: requestBody.riskLevel
      - text: Record a {event_type} risk event for app {app_id} from IP {ip}.
        slots:
          event_type: requestBody.riskEventType
          app_id: requestBody.appId
          ip: requestBody.ipAddress
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a service principal risk detection
      effect: read
      questions:
      - What details, like location and detection time, does one service principal risk detection hold?
      - Can I look up a single workload identity risk event by its id?
      instructions:
      - text: Get service principal risk detection {detection_id}.
        slots:
          detection_id: path.servicePrincipalRiskDetection-id
      - text: Show the risk level, state and IP address of detection {detection_id}.
        slots:
          detection_id: path.servicePrincipalRiskDetection-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a service principal risk detection
      effect: destructive
      questions:
      - Can I delete a risk detection recorded against a service principal?
      - Is removing a workload identity risk event reversible?
      instructions:
      - text: Delete service principal risk detection {detection_id}.
        slots:
          detection_id: path.servicePrincipalRiskDetection-id
      - text: Remove risk detection {detection_id} only if its ETag is {etag}.
        slots:
          detection_id: path.servicePrincipalRiskDetection-id
          etag: header.If-Match
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a service principal risk detection
      effect: write
      questions:
      - Can I change the risk state of a service principal risk detection after review?
      - Which fields of an existing workload identity risk detection can be patched?
      instructions:
      - text: Set the risk state of detection {detection_id} to {risk_state}.
        slots:
          detection_id: path.servicePrincipalRiskDetection-id
          risk_state: requestBody.riskState
      - text: Update risk detection {detection_id} with risk detail {risk_detail}.
        slots:
          detection_id: path.servicePrincipalRiskDetection-id
          risk_detail: requestBody.riskDetail
      method: generated
      generated: '2026-10-01'
- target: $.paths['/identityProtection/servicePrincipalRiskDetections/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count service principal risk detections
      effect: read
      questions:
      - How many risk detections are there for service principals in my tenant?
      - Can I get just a total of workload identity risk events?
      instructions:
      - text: Count the service principal risk detections.
      - text: Return only the number of workload identity risk detections.
      method: generated
      generated: '2026-10-01'