Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Identity.SignIns Policies.cross Tenant Access Policy API

31 actions 31 updates phrasing extends openapi/azure-ad-policies-crosstenantaccesspolicy-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 31 · first 16 shown; the file carries all of them

$.info
$.paths['/policies/crossTenantAccessPolicy'].get
$.paths['/policies/crossTenantAccessPolicy'].delete
$.paths['/policies/crossTenantAccessPolicy'].patch
$.paths['/policies/crossTenantAccessPolicy/default'].get
$.paths['/policies/crossTenantAccessPolicy/default'].delete
$.paths['/policies/crossTenantAccessPolicy/default'].patch
$.paths['/policies/crossTenantAccessPolicy/default/microsoft.graph.resetToSystemDefault'].post
$.paths['/policies/crossTenantAccessPolicy/partners'].get
$.paths['/policies/crossTenantAccessPolicy/partners'].post
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].get
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].delete
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].patch
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].get
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].put
$.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].delete

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Identity.SignIns Policies.cross Tenant Access Policy API
  version: 1.0.0
extends: openapi/azure-ad-policies-crosstenantaccesspolicy-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 30
- target: $.paths['/policies/crossTenantAccessPolicy'].get
  update:
    x-apievangelist-phrasing:
      intent: View the tenant's cross-tenant access policy
      effect: read
      questions:
      - How do I see my tenant's overall cross-tenant access policy in Microsoft Entra ID?
      - Which cloud endpoints are allowed in our cross-tenant access policy right now?
      instructions:
      - text: Show me the top-level cross-tenant access policy for our tenant.
      - text: Get the cross-tenant access policy and include only {fields}.
        slots:
          fields: query.$select
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the cross-tenant access policy object
      effect: destructive
      questions:
      - Can the whole cross-tenant access policy object be deleted from the policies root?
      - What happens if I remove the entire cross-tenant access policy rather than one partner?
      instructions:
      - text: Delete the entire cross-tenant access policy object from our tenant's policies.
      - text: Remove the whole cross-tenant access policy only if its ETag still matches {etag}.
        slots:
          etag: header.If-Match
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update the top-level cross-tenant access policy
      effect: write
      questions:
      - Can I change which cloud endpoints are allowed for cross-tenant collaboration?
      - How do I edit the overall cross-tenant access policy object itself?
      instructions:
      - text: Set the allowed cloud endpoints on our cross-tenant access policy to {endpoints}.
        slots:
          endpoints: requestBody.allowedCloudEndpoints
      - text: Patch the top-level cross-tenant access policy so collaboration with other clouds is limited to the ones I list.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default'].get
  update:
    x-apievangelist-phrasing:
      intent: View the default cross-tenant access settings
      effect: read
      questions:
      - What are the default inbound and outbound B2B settings that apply to tenants without a partner config?
      - Is our cross-tenant default still the service default or has it been customized?
      instructions:
      - text: Show the default cross-tenant access configuration for tenants that have no partner-specific settings.
      - text: Get the cross-tenant default configuration returning only {fields}.
        slots:
          fields: query.$select
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the default cross-tenant configuration
      effect: destructive
      questions:
      - Can I delete the default configuration object under the cross-tenant access policy?
      - Is there a delete call for the cross-tenant default settings navigation property?
      instructions:
      - text: Delete the default configuration from our cross-tenant access policy.
      - text: Remove the cross-tenant default configuration if its ETag matches {etag}.
        slots:
          etag: header.If-Match
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change default cross-tenant access settings
      effect: write
      questions:
      - How can I block outbound B2B collaboration by default for every external tenant?
      - Can I trust MFA claims from all external tenants by default?
      instructions:
      - text: Update the default B2B collaboration inbound settings to {settings}.
        slots:
          settings: requestBody.b2bCollaborationInbound
      - text: Change the default inbound trust for all external tenants to {trust}.
        slots:
          trust: requestBody.inboundTrust
      - text: Set the default tenant restrictions for cross-tenant access to {restrictions}.
        slots:
          restrictions: requestBody.tenantRestrictions
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/default/microsoft.graph.resetToSystemDefault'].post
  update:
    x-apievangelist-phrasing:
      intent: Reset default cross-tenant settings to system default
      effect: destructive
      questions:
      - How do I undo all my customizations to the default cross-tenant access settings?
      - Can I put the cross-tenant default configuration back to what Microsoft ships?
      instructions:
      - text: Reset our default cross-tenant access configuration back to the system default.
      - text: Discard every change to the cross-tenant default settings and restore the service default.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners'].get
  update:
    x-apievangelist-phrasing:
      intent: List partner-specific cross-tenant configurations
      effect: read
      questions:
      - Which external tenants have their own partner configuration in our cross-tenant access policy?
      - Can I list partner configurations along with their user synchronization policies?
      instructions:
      - text: List every partner configuration in our cross-tenant access policy.
      - text: List cross-tenant partner configurations matching {filter}.
        slots:
          filter: query.$filter
      - text: List partner configurations and expand {relationship}.
        slots:
          relationship: query.$expand
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a partner tenant to cross-tenant access
      effect: write
      questions:
      - How do I set custom B2B settings for one specific external tenant?
      - Can I mark a partner tenant as a service provider when I add it?
      instructions:
      - text: Create a partner configuration for tenant {tenantId}.
        slots:
          tenantId: requestBody.tenantId
      - text: Add partner tenant {tenantId} with inbound trust set to {trust}.
        slots:
          tenantId: requestBody.tenantId
          trust: requestBody.inboundTrust
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one partner's cross-tenant configuration
      effect: read
      questions:
      - What cross-tenant settings have we configured for a particular partner tenant?
      - Does a specific partner tenant have inbound MFA trust enabled?
      instructions:
      - text: Show the partner configuration for tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Get the inbound trust settings configured for partner tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove a partner's cross-tenant configuration
      effect: destructive
      questions:
      - How do I remove the custom settings for a partner tenant so it falls back to defaults?
      - Do I need to delete a partner's user sync policy before deleting the partner configuration?
      instructions:
      - text: Delete the partner configuration for tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Remove partner tenant {tenantId} from our cross-tenant access policy.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a partner's cross-tenant settings
      effect: write
      questions:
      - Can I change B2B direct connect settings for one partner tenant I already configured?
      - How would I turn on automatic user consent for an existing partner tenant?
      instructions:
      - text: Update B2B direct connect inbound for partner {tenantId} to {settings}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
          settings: requestBody.b2bDirectConnectInbound
      - text: Set automatic user consent settings for existing partner {tenantId} to {consent}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
          consent: requestBody.automaticUserConsentSettings
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a partner's user synchronization policy
      effect: read
      questions:
      - Is user synchronization from a partner tenant into ours turned on?
      - What cross-tenant sync policy is set for a given partner?
      instructions:
      - text: Show the user synchronization policy for partner tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Check whether inbound user sync is allowed from partner {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].put
  update:
    x-apievangelist-phrasing:
      intent: Create a partner's user synchronization policy
      effect: write
      questions:
      - How do I allow users from a partner tenant to be synced into our directory?
      - Can I name the cross-tenant sync policy when I create it for a partner?
      instructions:
      - text: Create a user sync policy for partner {tenantId} with inbound sync set to {userSyncInbound}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
          userSyncInbound: requestBody.userSyncInbound
      - text: Set up cross-tenant user synchronization for partner {tenantId} named {name}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
          name: requestBody.displayName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a partner's user synchronization policy
      effect: destructive
      questions:
      - How do I stop syncing users in from a partner tenant?
      - Can I remove a partner's sync policy without deleting the partner configuration itself?
      instructions:
      - text: Delete the user synchronization policy for partner {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Turn off cross-tenant user sync from partner {tenantId} by removing its sync policy.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a partner's service provider constraints
      effect: read
      questions:
      - What service provider constraints apply to a partner tenant marked as a service provider?
      - Where can I read the service provider restrictions on a partner configuration?
      instructions:
      - text: Show the service provider constraints for partner tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Get service provider constraints on partner {tenantId} returning only {fields}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
          fields: query.$select
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove a partner's service provider constraints
      effect: destructive
      questions:
      - Can I clear the service provider constraints from a partner tenant configuration?
      - Is it possible to drop service provider restrictions for one partner?
      instructions:
      - text: Delete the service provider constraints for partner tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Clear service provider restrictions on partner {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a partner's service provider constraints
      effect: write
      questions:
      - How do I modify the service provider constraints on an existing partner tenant?
      - Can service provider constraints be patched separately from the rest of the partner config?
      instructions:
      - text: Update the service provider constraints for partner tenant {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      - text: Patch the service provider constraint object on partner {tenantId}.
        slots:
          tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/partners/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count partner cross-tenant configurations
      effect: read
      questions:
      - How many external tenants have partner-specific cross-tenant settings?
      - Can I count only the partner configurations matching a filter?
      instructions:
      - text: Count the partner configurations in our cross-tenant access policy.
      - text: Count cross-tenant partner configurations that match {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates'].get
  update:
    x-apievangelist-phrasing:
      intent: View multitenant organization policy templates
      effect: read
      questions:
      - What base policy templates exist for our multitenant organization settings?
      - Can I see both multitenant org templates in a single call?
      instructions:
      - text: Show the cross-tenant access policy templates container for our multitenant organization.
      - text: Get the multitenant organization templates and expand {relationship}.
        slots:
          relationship: query.$expand
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the multitenant organization templates
      effect: destructive
      questions:
      - Is there a way to delete the templates container under the cross-tenant access policy?
      - Can the multitenant organization base policy templates be removed?
      instructions:
      - text: Delete the templates container from our cross-tenant access policy.
      - text: Remove the multitenant organization templates container if its ETag matches {etag}.
        slots:
          etag: header.If-Match
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update the multitenant organization templates container
      effect: write
      questions:
      - Can I update both the identity sync and partner configuration templates together?
      - How do I patch the multitenant organization templates container as a whole?
      instructions:
      - text: Update the templates container with partner configuration template {template}.
        slots:
          template: requestBody.multiTenantOrganizationPartnerConfiguration
      - text: Patch the templates container setting the identity sync template to {template}.
        slots:
          template: requestBody.multiTenantOrganizationIdentitySynchronization
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the multitenant org user sync template
      effect: read
      questions:
      - What user synchronization settings does our multitenant organization template apply?
      - Which tenants does the multitenant org identity sync template apply to?
      instructions:
      - text: Show the multitenant organization identity synchronization template.
      - text: Get the user sync template for our multitenant org with only {fields}.
        slots:
          fields: query.$select
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the multitenant org user sync template
      effect: destructive
      questions:
      - Can I delete the identity synchronization template for our multitenant organization?
      - Is the multitenant org user sync template something I can remove outright?
      instructions:
      - text: Delete the multitenant organization identity synchronization template.
      - text: Remove the multitenant org user sync template if its ETag matches {etag}.
        slots:
          etag: header.If-Match
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update the multitenant org user sync template
      effect: write
      questions:
      - How do I enable inbound user sync in the multitenant organization template?
      - Can I control which tenants the multitenant org sync template is applied to?
      instructions:
      - text: Set inbound user sync in the multitenant org identity sync template to {userSyncInbound}.
        slots:
          userSyncInbound: requestBody.userSyncInbound
      - text: Change the application level of the multitenant org user sync template to {level}.
        slots:
          level: requestBody.templateApplicationLevel
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization/microsoft.graph.resetToDefaultSettings'].post
  update:
    x-apievangelist-phrasing:
      intent: Reset the multitenant org user sync template
      effect: destructive
      questions:
      - How do I restore the multitenant org identity sync template to its default values?
      - Can I undo my edits to the user synchronization template for our multitenant organization?
      instructions:
      - text: Reset the multitenant organization identity synchronization template to default settings.
      - text: Restore default values on our multitenant org user sync template.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the multitenant org partner config template
      effect: read
      questions:
      - What inbound and outbound partner settings does our multitenant organization template set?
      - Does the multitenant org partner template trust MFA from member tenants?
      instructions:
      - text: Show the multitenant organization partner configuration template.
      - text: Get the multitenant org partner configuration template returning {fields}.
        slots:
          fields: query.$select
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the multitenant org partner config template
      effect: destructive
      questions:
      - Can the partner configuration template for our multitenant organization be deleted?
      - Is there a delete for the multitenant org inbound and outbound partner template?
      instructions:
      - text: Delete the multitenant organization partner configuration template.
      - text: Remove the multitenant org partner template if its ETag matches {etag}.
        slots:
          etag: header.If-Match
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update the multitenant org partner config template
      effect: write
      questions:
      - How do I change B2B collaboration settings in the multitenant organization partner template?
      - Can I turn on automatic user consent across our multitenant organization via its template?
      instructions:
      - text: Set B2B collaboration outbound in the multitenant org partner template to {settings}.
        slots:
          settings: requestBody.b2bCollaborationOutbound
      - text: Update inbound trust in the multitenant org partner template to {trust}.
        slots:
          trust: requestBody.inboundTrust
      method: generated
      generated: '2026-10-01'
- target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration/microsoft.graph.resetToDefaultSettings'].post
  update:
    x-apievangelist-phrasing:
      intent: Reset the multitenant org partner config template
      effect: destructive
      questions:
      - How can I put the multitenant org partner configuration template back to defaults?
      - Can I undo changes to the inbound and outbound template for our multitenant organization?
      instructions:
      - text: Reset the multitenant organization partner configuration template to default settings.
      - text: Restore default values on our multitenant org partner template.
      method: generated
      generated: '2026-10-01'