Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Identity.SignIns Policies.cross Tenant Access Policy API
31 actions
31 updates
phrasing
extends
openapi/azure-ad-policies-crosstenantaccesspolicy-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
What the actions change
x-apievangelist-phrasing
Targets 31 · first 16 shown; the file carries all of them
$.info
$.paths['/policies/crossTenantAccessPolicy'].get
$.paths['/policies/crossTenantAccessPolicy'].delete
$.paths['/policies/crossTenantAccessPolicy'].patch
$.paths['/policies/crossTenantAccessPolicy/default'].get
$.paths['/policies/crossTenantAccessPolicy/default'].delete
$.paths['/policies/crossTenantAccessPolicy/default'].patch
$.paths['/policies/crossTenantAccessPolicy/default/microsoft.graph.resetToSystemDefault'].post
$.paths['/policies/crossTenantAccessPolicy/partners'].get
$.paths['/policies/crossTenantAccessPolicy/partners'].post
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].get
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].delete
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].patch
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].get
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].put
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].delete
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Identity.SignIns Policies.cross Tenant Access Policy API
version: 1.0.0
extends: openapi/azure-ad-policies-crosstenantaccesspolicy-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 30
- target: $.paths['/policies/crossTenantAccessPolicy'].get
update:
x-apievangelist-phrasing:
intent: View the tenant's cross-tenant access policy
effect: read
questions:
- How do I see my tenant's overall cross-tenant access policy in Microsoft Entra ID?
- Which cloud endpoints are allowed in our cross-tenant access policy right now?
instructions:
- text: Show me the top-level cross-tenant access policy for our tenant.
- text: Get the cross-tenant access policy and include only {fields}.
slots:
fields: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy'].delete
update:
x-apievangelist-phrasing:
intent: Delete the cross-tenant access policy object
effect: destructive
questions:
- Can the whole cross-tenant access policy object be deleted from the policies root?
- What happens if I remove the entire cross-tenant access policy rather than one partner?
instructions:
- text: Delete the entire cross-tenant access policy object from our tenant's policies.
- text: Remove the whole cross-tenant access policy only if its ETag still matches {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy'].patch
update:
x-apievangelist-phrasing:
intent: Update the top-level cross-tenant access policy
effect: write
questions:
- Can I change which cloud endpoints are allowed for cross-tenant collaboration?
- How do I edit the overall cross-tenant access policy object itself?
instructions:
- text: Set the allowed cloud endpoints on our cross-tenant access policy to {endpoints}.
slots:
endpoints: requestBody.allowedCloudEndpoints
- text: Patch the top-level cross-tenant access policy so collaboration with other clouds is limited to the ones I list.
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default'].get
update:
x-apievangelist-phrasing:
intent: View the default cross-tenant access settings
effect: read
questions:
- What are the default inbound and outbound B2B settings that apply to tenants without a partner config?
- Is our cross-tenant default still the service default or has it been customized?
instructions:
- text: Show the default cross-tenant access configuration for tenants that have no partner-specific settings.
- text: Get the cross-tenant default configuration returning only {fields}.
slots:
fields: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default'].delete
update:
x-apievangelist-phrasing:
intent: Delete the default cross-tenant configuration
effect: destructive
questions:
- Can I delete the default configuration object under the cross-tenant access policy?
- Is there a delete call for the cross-tenant default settings navigation property?
instructions:
- text: Delete the default configuration from our cross-tenant access policy.
- text: Remove the cross-tenant default configuration if its ETag matches {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default'].patch
update:
x-apievangelist-phrasing:
intent: Change default cross-tenant access settings
effect: write
questions:
- How can I block outbound B2B collaboration by default for every external tenant?
- Can I trust MFA claims from all external tenants by default?
instructions:
- text: Update the default B2B collaboration inbound settings to {settings}.
slots:
settings: requestBody.b2bCollaborationInbound
- text: Change the default inbound trust for all external tenants to {trust}.
slots:
trust: requestBody.inboundTrust
- text: Set the default tenant restrictions for cross-tenant access to {restrictions}.
slots:
restrictions: requestBody.tenantRestrictions
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default/microsoft.graph.resetToSystemDefault'].post
update:
x-apievangelist-phrasing:
intent: Reset default cross-tenant settings to system default
effect: destructive
questions:
- How do I undo all my customizations to the default cross-tenant access settings?
- Can I put the cross-tenant default configuration back to what Microsoft ships?
instructions:
- text: Reset our default cross-tenant access configuration back to the system default.
- text: Discard every change to the cross-tenant default settings and restore the service default.
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners'].get
update:
x-apievangelist-phrasing:
intent: List partner-specific cross-tenant configurations
effect: read
questions:
- Which external tenants have their own partner configuration in our cross-tenant access policy?
- Can I list partner configurations along with their user synchronization policies?
instructions:
- text: List every partner configuration in our cross-tenant access policy.
- text: List cross-tenant partner configurations matching {filter}.
slots:
filter: query.$filter
- text: List partner configurations and expand {relationship}.
slots:
relationship: query.$expand
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners'].post
update:
x-apievangelist-phrasing:
intent: Add a partner tenant to cross-tenant access
effect: write
questions:
- How do I set custom B2B settings for one specific external tenant?
- Can I mark a partner tenant as a service provider when I add it?
instructions:
- text: Create a partner configuration for tenant {tenantId}.
slots:
tenantId: requestBody.tenantId
- text: Add partner tenant {tenantId} with inbound trust set to {trust}.
slots:
tenantId: requestBody.tenantId
trust: requestBody.inboundTrust
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].get
update:
x-apievangelist-phrasing:
intent: Get one partner's cross-tenant configuration
effect: read
questions:
- What cross-tenant settings have we configured for a particular partner tenant?
- Does a specific partner tenant have inbound MFA trust enabled?
instructions:
- text: Show the partner configuration for tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Get the inbound trust settings configured for partner tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].delete
update:
x-apievangelist-phrasing:
intent: Remove a partner's cross-tenant configuration
effect: destructive
questions:
- How do I remove the custom settings for a partner tenant so it falls back to defaults?
- Do I need to delete a partner's user sync policy before deleting the partner configuration?
instructions:
- text: Delete the partner configuration for tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Remove partner tenant {tenantId} from our cross-tenant access policy.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].patch
update:
x-apievangelist-phrasing:
intent: Update a partner's cross-tenant settings
effect: write
questions:
- Can I change B2B direct connect settings for one partner tenant I already configured?
- How would I turn on automatic user consent for an existing partner tenant?
instructions:
- text: Update B2B direct connect inbound for partner {tenantId} to {settings}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
settings: requestBody.b2bDirectConnectInbound
- text: Set automatic user consent settings for existing partner {tenantId} to {consent}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
consent: requestBody.automaticUserConsentSettings
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].get
update:
x-apievangelist-phrasing:
intent: Get a partner's user synchronization policy
effect: read
questions:
- Is user synchronization from a partner tenant into ours turned on?
- What cross-tenant sync policy is set for a given partner?
instructions:
- text: Show the user synchronization policy for partner tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Check whether inbound user sync is allowed from partner {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].put
update:
x-apievangelist-phrasing:
intent: Create a partner's user synchronization policy
effect: write
questions:
- How do I allow users from a partner tenant to be synced into our directory?
- Can I name the cross-tenant sync policy when I create it for a partner?
instructions:
- text: Create a user sync policy for partner {tenantId} with inbound sync set to {userSyncInbound}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
userSyncInbound: requestBody.userSyncInbound
- text: Set up cross-tenant user synchronization for partner {tenantId} named {name}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
name: requestBody.displayName
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].delete
update:
x-apievangelist-phrasing:
intent: Delete a partner's user synchronization policy
effect: destructive
questions:
- How do I stop syncing users in from a partner tenant?
- Can I remove a partner's sync policy without deleting the partner configuration itself?
instructions:
- text: Delete the user synchronization policy for partner {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Turn off cross-tenant user sync from partner {tenantId} by removing its sync policy.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].get
update:
x-apievangelist-phrasing:
intent: Get a partner's service provider constraints
effect: read
questions:
- What service provider constraints apply to a partner tenant marked as a service provider?
- Where can I read the service provider restrictions on a partner configuration?
instructions:
- text: Show the service provider constraints for partner tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Get service provider constraints on partner {tenantId} returning only {fields}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
fields: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].delete
update:
x-apievangelist-phrasing:
intent: Remove a partner's service provider constraints
effect: destructive
questions:
- Can I clear the service provider constraints from a partner tenant configuration?
- Is it possible to drop service provider restrictions for one partner?
instructions:
- text: Delete the service provider constraints for partner tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Clear service provider restrictions on partner {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].patch
update:
x-apievangelist-phrasing:
intent: Update a partner's service provider constraints
effect: write
questions:
- How do I modify the service provider constraints on an existing partner tenant?
- Can service provider constraints be patched separately from the rest of the partner config?
instructions:
- text: Update the service provider constraints for partner tenant {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
- text: Patch the service provider constraint object on partner {tenantId}.
slots:
tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/$count'].get
update:
x-apievangelist-phrasing:
intent: Count partner cross-tenant configurations
effect: read
questions:
- How many external tenants have partner-specific cross-tenant settings?
- Can I count only the partner configurations matching a filter?
instructions:
- text: Count the partner configurations in our cross-tenant access policy.
- text: Count cross-tenant partner configurations that match {filter}.
slots:
filter: query.$filter
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates'].get
update:
x-apievangelist-phrasing:
intent: View multitenant organization policy templates
effect: read
questions:
- What base policy templates exist for our multitenant organization settings?
- Can I see both multitenant org templates in a single call?
instructions:
- text: Show the cross-tenant access policy templates container for our multitenant organization.
- text: Get the multitenant organization templates and expand {relationship}.
slots:
relationship: query.$expand
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates'].delete
update:
x-apievangelist-phrasing:
intent: Delete the multitenant organization templates
effect: destructive
questions:
- Is there a way to delete the templates container under the cross-tenant access policy?
- Can the multitenant organization base policy templates be removed?
instructions:
- text: Delete the templates container from our cross-tenant access policy.
- text: Remove the multitenant organization templates container if its ETag matches {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates'].patch
update:
x-apievangelist-phrasing:
intent: Update the multitenant organization templates container
effect: write
questions:
- Can I update both the identity sync and partner configuration templates together?
- How do I patch the multitenant organization templates container as a whole?
instructions:
- text: Update the templates container with partner configuration template {template}.
slots:
template: requestBody.multiTenantOrganizationPartnerConfiguration
- text: Patch the templates container setting the identity sync template to {template}.
slots:
template: requestBody.multiTenantOrganizationIdentitySynchronization
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].get
update:
x-apievangelist-phrasing:
intent: Get the multitenant org user sync template
effect: read
questions:
- What user synchronization settings does our multitenant organization template apply?
- Which tenants does the multitenant org identity sync template apply to?
instructions:
- text: Show the multitenant organization identity synchronization template.
- text: Get the user sync template for our multitenant org with only {fields}.
slots:
fields: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].delete
update:
x-apievangelist-phrasing:
intent: Delete the multitenant org user sync template
effect: destructive
questions:
- Can I delete the identity synchronization template for our multitenant organization?
- Is the multitenant org user sync template something I can remove outright?
instructions:
- text: Delete the multitenant organization identity synchronization template.
- text: Remove the multitenant org user sync template if its ETag matches {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].patch
update:
x-apievangelist-phrasing:
intent: Update the multitenant org user sync template
effect: write
questions:
- How do I enable inbound user sync in the multitenant organization template?
- Can I control which tenants the multitenant org sync template is applied to?
instructions:
- text: Set inbound user sync in the multitenant org identity sync template to {userSyncInbound}.
slots:
userSyncInbound: requestBody.userSyncInbound
- text: Change the application level of the multitenant org user sync template to {level}.
slots:
level: requestBody.templateApplicationLevel
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization/microsoft.graph.resetToDefaultSettings'].post
update:
x-apievangelist-phrasing:
intent: Reset the multitenant org user sync template
effect: destructive
questions:
- How do I restore the multitenant org identity sync template to its default values?
- Can I undo my edits to the user synchronization template for our multitenant organization?
instructions:
- text: Reset the multitenant organization identity synchronization template to default settings.
- text: Restore default values on our multitenant org user sync template.
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].get
update:
x-apievangelist-phrasing:
intent: Get the multitenant org partner config template
effect: read
questions:
- What inbound and outbound partner settings does our multitenant organization template set?
- Does the multitenant org partner template trust MFA from member tenants?
instructions:
- text: Show the multitenant organization partner configuration template.
- text: Get the multitenant org partner configuration template returning {fields}.
slots:
fields: query.$select
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].delete
update:
x-apievangelist-phrasing:
intent: Delete the multitenant org partner config template
effect: destructive
questions:
- Can the partner configuration template for our multitenant organization be deleted?
- Is there a delete for the multitenant org inbound and outbound partner template?
instructions:
- text: Delete the multitenant organization partner configuration template.
- text: Remove the multitenant org partner template if its ETag matches {etag}.
slots:
etag: header.If-Match
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].patch
update:
x-apievangelist-phrasing:
intent: Update the multitenant org partner config template
effect: write
questions:
- How do I change B2B collaboration settings in the multitenant organization partner template?
- Can I turn on automatic user consent across our multitenant organization via its template?
instructions:
- text: Set B2B collaboration outbound in the multitenant org partner template to {settings}.
slots:
settings: requestBody.b2bCollaborationOutbound
- text: Update inbound trust in the multitenant org partner template to {trust}.
slots:
trust: requestBody.inboundTrust
method: generated
generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration/microsoft.graph.resetToDefaultSettings'].post
update:
x-apievangelist-phrasing:
intent: Reset the multitenant org partner config template
effect: destructive
questions:
- How can I put the multitenant org partner configuration template back to defaults?
- Can I undo changes to the inbound and outbound template for our multitenant organization?
instructions:
- text: Reset the multitenant organization partner configuration template to default settings.
- text: Restore default values on our multitenant org partner template.
method: generated
generated: '2026-10-01'