Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Identity.Governance Role Management.rbac Application API

225 actions 225 updates phrasing extends openapi/azure-ad-rolemanagement-rbacapplication-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 225 · first 16 shown; the file carries all of them

$.info
$.paths['/roleManagement/directory'].get
$.paths['/roleManagement/directory'].delete
$.paths['/roleManagement/directory'].patch
$.paths['/roleManagement/directory/resourceNamespaces'].get
$.paths['/roleManagement/directory/resourceNamespaces'].post
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}'].get
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}'].delete
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}'].patch
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions'].get
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions'].post
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/{unifiedRbacResourceAction-id}'].get
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/{unifiedRbacResourceAction-id}'].delete
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/{unifiedRbacResourceAction-id}'].patch
$.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/$count'].get
$.paths['/roleManagement/directory/resourceNamespaces/$count'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Identity.Governance Role Management.rbac Application API
  version: 1.0.0
extends: openapi/azure-ad-rolemanagement-rbacapplication-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 224
- target: $.paths['/roleManagement/directory'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the directory role management container
      effect: read
      questions:
      - What does the role management directory container expose in Entra ID?
      - Can I read the directory RBAC provider object that holds role definitions and assignments?
      instructions:
      - text: Get the directory role management container.
      - text: Show me the directory RBAC provider root with {expand} expanded.
        slots:
          expand: query.$expand
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the directory role management container
      effect: destructive
      questions:
      - Is it possible to delete the whole directory RBAC provider navigation property?
      - Can I remove the roleManagement directory object itself?
      instructions:
      - text: Delete the directory role management container.
      - text: Remove the directory RBAC provider object from role management.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update the directory role management container
      effect: write
      questions:
      - Can I patch the directory RBAC provider object itself rather than one role?
      - Which collections can be set when updating the directory role management container?
      instructions:
      - text: Update the directory role management container with resource namespaces {namespaces}.
        slots:
          namespaces: requestBody.resourceNamespaces
      - text: Patch the directory RBAC provider so its role definitions are {definitions}.
        slots:
          definitions: requestBody.roleDefinitions
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces'].get
  update:
    x-apievangelist-phrasing:
      intent: List directory resource namespaces
      effect: read
      questions:
      - Which resource namespaces exist for directory role permissions?
      - Where do I see all RBAC resource namespaces such as microsoft.directory?
      instructions:
      - text: List all resource namespaces in the directory RBAC provider.
      - text: Show the first {top} directory resource namespaces.
        slots:
          top: query.$top
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a directory resource namespace
      effect: write
      questions:
      - Can I add a new resource namespace to the directory RBAC provider?
      - What fields does a new directory resource namespace take?
      instructions:
      - text: Create a directory resource namespace named {name}.
        slots:
          name: requestBody.name
      - text: Add namespace {name} with resource actions {actions} to the directory provider.
        slots:
          name: requestBody.name
          actions: requestBody.resourceActions
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a directory resource namespace
      effect: read
      questions:
      - How can I look up a single directory resource namespace by its ID?
      - What does one directory resource namespace contain?
      instructions:
      - text: Get directory resource namespace {namespace}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Show the details of resource namespace {namespace} in the directory provider.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a directory resource namespace
      effect: destructive
      questions:
      - Can I remove a resource namespace from the directory RBAC provider?
      - What ID do I need to delete a directory resource namespace?
      instructions:
      - text: Delete directory resource namespace {namespace}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Remove resource namespace {namespace} from directory role management.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a directory resource namespace
      effect: write
      questions:
      - Can I rename a directory resource namespace?
      - Is there a way to change the resource actions listed under a directory namespace in one patch?
      instructions:
      - text: Rename directory resource namespace {namespace} to {name}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
          name: requestBody.name
      - text: Replace the resource actions on directory namespace {namespace} with {actions}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
          actions: requestBody.resourceActions
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions'].get
  update:
    x-apievangelist-phrasing:
      intent: List actions in a directory resource namespace
      effect: read
      questions:
      - Which resource actions are defined in a directory resource namespace?
      - Where can I find the permission action strings under a directory namespace?
      instructions:
      - text: List resource actions in directory namespace {namespace}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Show every action verb defined under directory resource namespace {namespace}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a resource action to a directory namespace
      effect: write
      questions:
      - Can I add a custom resource action to a directory resource namespace?
      - Is it possible to tie a new directory resource action to an authentication context?
      instructions:
      - text: Add resource action {name} with verb {verb} to directory namespace {namespace}.
        slots:
          name: requestBody.name
          verb: requestBody.actionVerb
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Create directory resource action {name} in namespace {namespace} described as {description}.
        slots:
          name: requestBody.name
          namespace: path.unifiedRbacResourceNamespace-id
          description: requestBody.description
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/{unifiedRbacResourceAction-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a resource action in a directory namespace
      effect: read
      questions:
      - What does a specific resource action in a directory namespace allow?
      - Can I check whether one directory resource action supports authentication context?
      instructions:
      - text: Get resource action {action} in directory namespace {namespace}.
        slots:
          action: path.unifiedRbacResourceAction-id
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Show the verb and scope of directory resource action {action} under {namespace}.
        slots:
          action: path.unifiedRbacResourceAction-id
          namespace: path.unifiedRbacResourceNamespace-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/{unifiedRbacResourceAction-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a resource action from a directory namespace
      effect: destructive
      questions:
      - How do I remove one resource action from a directory resource namespace?
      - Can a single directory permission action be deleted without dropping its namespace?
      instructions:
      - text: Delete resource action {action} from directory namespace {namespace}.
        slots:
          action: path.unifiedRbacResourceAction-id
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Remove directory action {action} in namespace {namespace}.
        slots:
          action: path.unifiedRbacResourceAction-id
          namespace: path.unifiedRbacResourceNamespace-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/{unifiedRbacResourceAction-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a resource action in a directory namespace
      effect: write
      questions:
      - Can I change the action verb of an existing directory resource action?
      - How do I make a directory resource action settable by authentication context?
      instructions:
      - text: Set authentication context {context} on directory resource action {action} in namespace {namespace}.
        slots:
          context: requestBody.authenticationContextId
          action: path.unifiedRbacResourceAction-id
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Update the description of directory action {action} under namespace {namespace} to {description}.
        slots:
          action: path.unifiedRbacResourceAction-id
          namespace: path.unifiedRbacResourceNamespace-id
          description: requestBody.description
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/{unifiedRbacResourceNamespace-id}/resourceActions/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count actions in a directory resource namespace
      effect: read
      questions:
      - How many resource actions does a directory resource namespace hold?
      - Can I get just the count of actions in one directory namespace?
      instructions:
      - text: Count the resource actions in directory namespace {namespace}.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      - text: Tell me how many actions directory namespace {namespace} defines.
        slots:
          namespace: path.unifiedRbacResourceNamespace-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/resourceNamespaces/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count directory resource namespaces
      effect: read
      questions:
      - How many resource namespaces does the directory RBAC provider have?
      - Is there a quick way to count directory resource namespaces without listing them?
      instructions:
      - text: Count the directory resource namespaces.
      - text: Give me the number of resource namespaces in directory role management.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments'].get
  update:
    x-apievangelist-phrasing:
      intent: List directory role assignments
      effect: read
      questions:
      - Who has which Entra directory roles assigned in my tenant?
      - Can I filter directory role assignments by principal or role definition?
      - How do I list every directory role assignment?
      instructions:
      - text: List all directory role assignments.
      - text: List directory role assignments matching {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments'].post
  update:
    x-apievangelist-phrasing:
      intent: Assign a directory role to a principal
      effect: write
      questions:
      - How do I assign a directory role to a user?
      - Can I scope a directory role assignment to an administrative unit instead of the whole tenant?
      instructions:
      - text: Assign directory role {role} to principal {principal} at scope {scope}.
        slots:
          role: requestBody.roleDefinitionId
          principal: requestBody.principalId
          scope: requestBody.directoryScopeId
      - text: Grant principal {principal} the directory role {role} tenant-wide.
        slots:
          principal: requestBody.principalId
          role: requestBody.roleDefinitionId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a directory role assignment
      effect: read
      questions:
      - What does a single directory role assignment contain?
      - Can I look up one directory role assignment by its ID?
      instructions:
      - text: Get directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Show the principal, role and scope for directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove a directory role assignment
      effect: destructive
      questions:
      - How do I revoke a directory role from a user?
      - Can I delete a single directory role assignment by ID?
      instructions:
      - text: Delete directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Revoke the directory role granted by assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a directory role assignment
      effect: write
      questions:
      - Can I change the scope of an existing directory role assignment?
      - Is it possible to add a condition to a directory role assignment after it exists?
      instructions:
      - text: Change the directory scope of role assignment {assignment} to {scope}.
        slots:
          assignment: path.unifiedRoleAssignment-id
          scope: requestBody.directoryScopeId
      - text: Set condition {condition} on directory role assignment {assignment}.
        slots:
          condition: requestBody.condition
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}/appScope'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the app scope of a directory role assignment
      effect: read
      questions:
      - Which app-specific scope does a directory role assignment apply to?
      - Where can I see the app scope details of a directory role assignment?
      instructions:
      - text: Get the app scope of directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Show the app-specific scope attached to directory assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}/appScope'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the app scope of a directory role assignment
      effect: destructive
      questions:
      - Can I remove the app scope from a directory role assignment?
      - How do I clear an app-specific scope on a directory role assignment?
      instructions:
      - text: Delete the app scope on directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Clear the app-specific scope from directory assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}/appScope'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update the app scope of a directory role assignment
      effect: write
      questions:
      - Can I rename the app scope on a directory role assignment?
      - What fields can I change on a directory role assignment's app scope?
      instructions:
      - text: Set the app scope display name on directory assignment {assignment} to {name}.
        slots:
          assignment: path.unifiedRoleAssignment-id
          name: requestBody.displayName
      - text: Update the app scope type on directory role assignment {assignment} to {type}.
        slots:
          assignment: path.unifiedRoleAssignment-id
          type: requestBody.type
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}/directoryScope'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the scope object of a directory role assignment
      effect: read
      questions:
      - Which directory object is the scope of a directory role assignment?
      - Is a given directory role assignment scoped to an administrative unit or the whole tenant?
      instructions:
      - text: Get the scope object for directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Show what object directory role assignment {assignment} is scoped to.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}/principal'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the principal of a directory role assignment
      effect: read
      questions:
      - Who is the principal behind a directory role assignment?
      - Can I fetch the user or group that holds a given directory role assignment?
      instructions:
      - text: Get the principal of directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Show who received directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/{unifiedRoleAssignment-id}/roleDefinition'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the role granted by a directory role assignment
      effect: read
      questions:
      - Which role does a directory role assignment grant?
      - Where do I see the role definition behind a directory role assignment?
      instructions:
      - text: Get the role definition for directory role assignment {assignment}.
        slots:
          assignment: path.unifiedRoleAssignment-id
      - text: Show which role directory assignment {assignment} is for.
        slots:
          assignment: path.unifiedRoleAssignment-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignments/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count directory role assignments
      effect: read
      questions:
      - How many directory role assignments exist in my tenant?
      - Can I count directory role assignments without paging through them?
      instructions:
      - text: Count directory role assignments.
      - text: Count directory role assignments matching {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances'].get
  update:
    x-apievangelist-phrasing:
      intent: List active directory role assignment instances
      effect: read
      questions:
      - Which directory role assignments are active right now, including PIM activations?
      - Can I see active directory role instances that came from activating an eligible role?
      instructions:
      - text: List active directory role assignment instances.
      - text: List active directory role instances matching {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an active directory role assignment instance
      effect: write
      questions:
      - Can I create an active directory role assignment instance directly?
      - What start and end times does a new directory assignment schedule instance take?
      instructions:
      - text: Create a directory role assignment instance for schedule {schedule} from {start} to {end}.
        slots:
          schedule: requestBody.roleAssignmentScheduleId
          start: requestBody.startDateTime
          end: requestBody.endDateTime
      - text: Add an active directory assignment instance with assignment type {type}.
        slots:
          type: requestBody.assignmentType
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an active directory role assignment instance
      effect: read
      questions:
      - What does one active directory role assignment instance look like?
      - When does a particular active directory role instance start and end?
      instructions:
      - text: Get active directory role assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Show start and end times of directory assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an active directory role assignment instance
      effect: destructive
      questions:
      - Can I delete an active directory role assignment instance?
      - What do I need to remove a directory assignment schedule instance by ID?
      instructions:
      - text: Delete directory role assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Remove active directory assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update an active directory role assignment instance
      effect: write
      questions:
      - Can I change the end time of an active directory role assignment instance?
      - Which fields can be patched on a directory assignment schedule instance?
      instructions:
      - text: Set the end time of directory assignment instance {instance} to {end}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
          end: requestBody.endDateTime
      - text: Update member type on active directory role instance {instance} to {memberType}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
          memberType: requestBody.memberType
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}/activatedUsing'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the eligibility behind an active directory role
      effect: read
      questions:
      - Which eligible assignment was activated to produce an active directory role instance?
      - Can I trace an active directory role instance back to the eligibility it came from?
      instructions:
      - text: Get the eligibility used to activate directory assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Show which eligible role activation produced active directory instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}/appScope'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the app scope of an active directory role instance
      effect: read
      questions:
      - Is an active directory role instance scoped to a specific app?
      - Where do I find the app scope of an active directory assignment instance?
      instructions:
      - text: Get the app scope of active directory role instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Show app-specific scope details for directory assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}/directoryScope'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the scope object of an active directory role instance
      effect: read
      questions:
      - What directory object is an active directory role instance scoped to?
      - Can I see whether an active directory role instance covers an administrative unit?
      instructions:
      - text: Get the scope object of active directory role instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Show the directory object that assignment instance {instance} is scoped to.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}/principal'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the principal of an active directory role instance
      effect: read
      questions:
      - Who holds a given active directory role assignment instance?
      - Can I fetch the principal of an active directory role instance?
      instructions:
      - text: Get the principal of active directory role instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Show the user or group behind directory assignment instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/{unifiedRoleAssignmentScheduleInstance-id}/roleDefinition'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the role of an active directory role instance
      effect: read
      questions:
      - Which role is granted by an active directory role assignment instance?
      - Can I read the role definition behind an active directory role instance?
      instructions:
      - text: Get the role definition of active directory role instance {instance}.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      - text: Show which role directory assignment instance {instance} grants.
        slots:
          instance: path.unifiedRoleAssignmentScheduleInstance-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count active directory role assignment instances
      effect: read
      questions:
      - How many active directory role assignment instances are there?
      - Can I get a count of directory roles that are active at this moment?
      instructions:
      - text: Count active directory role assignment instances.
      - text: Tell me how many directory roles are active right now.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleInstances/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get
  update:
    x-apievangelist-phrasing:
      intent: List my active directory role instances
      effect: read
      questions:
      - Which directory roles are active for me right now?
      - Can I list only my own active directory role instances?
      instructions:
      - text: List my active directory role instances filtered on {on}.
        slots:
          'on': path.on
      - text: Show active directory role assignment instances where I am the {on}.
        slots:
          'on': path.on
      method: generated
      generated: '2026-10-01'
- target: $.paths['/roleManagement/directory/roleAssignmentScheduleRequests'].get
  update:
    x-apievangelist-phrasing:
      intent: List PIM directory role assignment requests
      effect: read
      questions:
      - What PIM requests for active directory role assignments have been made?
      - Can I see pending and granted directory role assignment requests?
      instructions:
      - text: List directory role assignment schedule requests.
      - text: List PIM directory assignment requests matching {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'


# --- truncated at 32 KB (176 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/azure-ad/refs/heads/main/overlays/azure-ad-rolemanagement-rbacapplication-api-phrasing-overlay.yaml