Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Applications Service Principals.directory Object API

67 actions 67 updates phrasing extends openapi/azure-ad-serviceprincipals-directoryobject-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 67 · first 16 shown; the file carries all of them

$.info
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.administrativeUnit'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.directoryRole'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.group'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Applications Service Principals.directory Object API
  version: 1.0.0
extends: openapi/azure-ad-serviceprincipals-directoryobject-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 66
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects'].get
  update:
    x-apievangelist-phrasing:
      intent: List objects a service principal created
      effect: read
      questions:
      - Which directory objects were created by a particular service principal?
      - Can I see everything an app's service principal has created in my tenant?
      instructions:
      - text: List all directory objects created by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show the first {top} objects that service principal {sp} created.
        slots:
          top: query.$top
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one object a service principal created
      effect: read
      questions:
      - What are the details of a single object that a service principal created?
      - Can I look up one specific created object by its id under its creating service principal?
      instructions:
      - text: Get created object {object} from service principal {sp}.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show me the directory object {object} that {sp} created.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a created object typed as a service principal
      effect: read
      questions:
      - Can I read a created object with its service principal properties rather than generic directory fields?
      - Is the object a service principal created itself a service principal, and what are its app details?
      instructions:
      - text: Get created object {object} of service principal {sp}, cast as a service principal.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Return created item {object} under {sp} with its full service principal fields.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count objects a service principal created
      effect: read
      questions:
      - How many directory objects has a given service principal created?
      - Is there a quick way to get just the total of created objects for an app without listing them?
      instructions:
      - text: Count the directory objects created by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Give me the number of created objects for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal'].get
  update:
    x-apievangelist-phrasing:
      intent: List service principals a service principal created
      effect: read
      questions:
      - Which service principals were created by another service principal?
      - Can I filter a service principal's created objects down to only service principals?
      instructions:
      - text: List only the service principals that {sp} created.
        slots:
          sp: path.servicePrincipal-id
      - text: Show created objects of {sp} that are service principals, first {top}.
        slots:
          sp: path.servicePrincipal-id
          top: query.$top
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count service principals a service principal created
      effect: read
      questions:
      - How many service principals has one service principal created?
      - What is the total of created objects that are themselves service principals?
      instructions:
      - text: Count the service principals created by {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many of the objects {sp} created are service principals.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf'].get
  update:
    x-apievangelist-phrasing:
      intent: List a service principal's direct memberships
      effect: read
      questions:
      - Which groups and directory roles is a service principal directly a member of?
      - Does the memberOf list for an app include nested group memberships?
      instructions:
      - text: List the groups and roles service principal {sp} directly belongs to.
        slots:
          sp: path.servicePrincipal-id
      - text: Show the direct, non-transitive memberships of {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one direct membership of a service principal
      effect: read
      questions:
      - Can I fetch a single group or role that a service principal is directly a member of?
      - What does one direct membership entry for a service principal look like?
      instructions:
      - text: Get direct membership {object} of service principal {sp}.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show the group or role {object} that {sp} is directly a member of.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.administrativeUnit'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a direct membership as an administrative unit
      effect: read
      questions:
      - Can I read one of a service principal's direct memberships as an administrative unit?
      - What are the admin unit details for a unit a service principal directly belongs to?
      instructions:
      - text: Get direct membership {unit} of {sp} as an administrative unit.
        slots:
          unit: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show administrative unit {unit} that service principal {sp} is directly in.
        slots:
          unit: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.directoryRole'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a direct membership as a directory role
      effect: read
      questions:
      - Can I read one of a service principal's direct memberships as a directory role?
      - Which role details come back for a role a service principal holds directly?
      instructions:
      - text: Get direct membership {role} of {sp} as a directory role.
        slots:
          role: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show directory role {role} that service principal {sp} directly holds.
        slots:
          role: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.group'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a direct membership as a group
      effect: read
      questions:
      - Can I read one of a service principal's direct memberships with its group properties?
      - What are the group details for a group an app is directly a member of?
      instructions:
      - text: Get direct membership {group} of {sp} as a group.
        slots:
          group: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show group {group} that service principal {sp} is directly a member of.
        slots:
          group: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count a service principal's direct memberships
      effect: read
      questions:
      - How many groups and roles is a service principal directly a member of?
      - What is the total of direct memberships for one app?
      instructions:
      - text: Count the direct memberships of service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Give me the number of groups and roles {sp} directly belongs to.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit'].get
  update:
    x-apievangelist-phrasing:
      intent: List admin units a service principal is directly in
      effect: read
      questions:
      - Which administrative units is a service principal directly a member of?
      - Can I narrow a service principal's direct memberships to administrative units only?
      instructions:
      - text: List the administrative units {sp} is directly a member of.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only admin-unit memberships held directly by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count admin units a service principal is directly in
      effect: read
      questions:
      - How many administrative units does a service principal directly belong to?
      - What is the count of direct admin-unit memberships for an app?
      instructions:
      - text: Count the administrative units {sp} is directly in.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many admin units service principal {sp} directly belongs to.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole'].get
  update:
    x-apievangelist-phrasing:
      intent: List directory roles a service principal holds directly
      effect: read
      questions:
      - Which directory roles has a service principal been directly assigned?
      - Can I list only the roles, not groups, that an app is directly a member of?
      instructions:
      - text: List the directory roles service principal {sp} holds directly.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only direct directory-role memberships for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count directory roles a service principal holds directly
      effect: read
      questions:
      - How many directory roles does a service principal directly hold?
      - What is the number of direct role memberships for an app?
      instructions:
      - text: Count the directory roles {sp} directly holds.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many roles service principal {sp} is directly assigned.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.group'].get
  update:
    x-apievangelist-phrasing:
      intent: List groups a service principal is directly in
      effect: read
      questions:
      - Which groups is a service principal directly a member of?
      - Can I see only the direct group memberships of an app, without roles?
      instructions:
      - text: List the groups service principal {sp} is directly a member of.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only direct group memberships for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.group/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count groups a service principal is directly in
      effect: read
      questions:
      - How many groups is a service principal directly a member of?
      - What is the direct group membership total for an app?
      instructions:
      - text: Count the groups {sp} is directly in.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many groups service principal {sp} directly belongs to.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects'].get
  update:
    x-apievangelist-phrasing:
      intent: List objects a service principal owns
      effect: read
      questions:
      - Which applications, groups or other objects does a service principal own?
      - Can I get every directory object owned by an app's service principal?
      instructions:
      - text: List all objects owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show the first {top} directory objects that {sp} owns.
        slots:
          top: query.$top
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one object a service principal owns
      effect: read
      questions:
      - Can I fetch a single owned object by id for a service principal?
      - What are the generic directory details of one object an app owns?
      instructions:
      - text: Get owned object {object} of service principal {sp}.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show the directory object {object} that {sp} owns.
        slots:
          object: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.application'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an owned object as an application
      effect: read
      questions:
      - Can I read an object a service principal owns with its application registration properties?
      - What app registration details come back for an application owned by a service principal?
      instructions:
      - text: Get owned object {app} of {sp} as an application.
        slots:
          app: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show application {app} that service principal {sp} owns.
        slots:
          app: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.appRoleAssignment'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an owned object as an app role assignment
      effect: read
      questions:
      - Can I read an owned object of a service principal as an app role assignment?
      - Which role and principal does an app role assignment owned by a service principal point to?
      instructions:
      - text: Get owned object {assignment} of {sp} as an app role assignment.
        slots:
          assignment: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show app role assignment {assignment} owned by service principal {sp}.
        slots:
          assignment: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.endpoint'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an owned object as an endpoint
      effect: read
      questions:
      - Can I read an owned object of a service principal as an endpoint?
      - What endpoint details are returned for one endpoint a service principal owns?
      instructions:
      - text: Get owned object {endpoint} of {sp} as an endpoint.
        slots:
          endpoint: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show endpoint {endpoint} owned by service principal {sp}.
        slots:
          endpoint: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.group'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an owned object as a group
      effect: read
      questions:
      - Can I read a group that a service principal owns with its group properties?
      - What group details come back for one group owned by an app?
      instructions:
      - text: Get owned object {group} of {sp} as a group.
        slots:
          group: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show group {group} that service principal {sp} owns.
        slots:
          group: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an owned object as a service principal
      effect: read
      questions:
      - Can I read another service principal that this service principal owns?
      - What app details come back for a service principal owned by a different one?
      instructions:
      - text: Get owned object {owned} of {sp} as a service principal.
        slots:
          owned: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show service principal {owned} that is owned by service principal {sp}.
        slots:
          owned: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count objects a service principal owns
      effect: read
      questions:
      - How many directory objects does a service principal own in total?
      - What is the owned-object count for one app?
      instructions:
      - text: Count all objects owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Give me the total number of owned objects for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.application'].get
  update:
    x-apievangelist-phrasing:
      intent: List applications a service principal owns
      effect: read
      questions:
      - Which application registrations does a service principal own?
      - Can I narrow a service principal's owned objects to applications only?
      instructions:
      - text: List the applications owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only application registrations that {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.application/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count applications a service principal owns
      effect: read
      questions:
      - How many application registrations does a service principal own?
      - What is the number of apps owned by one service principal?
      instructions:
      - text: Count the applications owned by {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many app registrations service principal {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.appRoleAssignment'].get
  update:
    x-apievangelist-phrasing:
      intent: List app role assignments a service principal owns
      effect: read
      questions:
      - Which app role assignments are owned by a service principal?
      - Can I filter a service principal's owned objects to app role assignments?
      instructions:
      - text: List the app role assignments owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only owned app role assignments for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.appRoleAssignment/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count app role assignments a service principal owns
      effect: read
      questions:
      - How many app role assignments does a service principal own?
      - What is the owned app role assignment total for an app?
      instructions:
      - text: Count the app role assignments owned by {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many app role assignments service principal {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.endpoint'].get
  update:
    x-apievangelist-phrasing:
      intent: List endpoints a service principal owns
      effect: read
      questions:
      - Which endpoints does a service principal own?
      - Can I see just the endpoint objects owned by an app's service principal?
      instructions:
      - text: List the endpoints owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only owned endpoint objects for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.endpoint/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count endpoints a service principal owns
      effect: read
      questions:
      - How many endpoints does a service principal own?
      - What is the owned endpoint total for one app?
      instructions:
      - text: Count the endpoints owned by {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many endpoint objects service principal {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.group'].get
  update:
    x-apievangelist-phrasing:
      intent: List groups a service principal owns
      effect: read
      questions:
      - Which groups are owned by a service principal?
      - Can I narrow an app's owned objects to groups only?
      instructions:
      - text: List the groups owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only the groups that {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.group/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count groups a service principal owns
      effect: read
      questions:
      - How many groups does a service principal own?
      - What is the number of groups owned by one app?
      instructions:
      - text: Count the groups owned by {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many groups service principal {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.servicePrincipal'].get
  update:
    x-apievangelist-phrasing:
      intent: List service principals a service principal owns
      effect: read
      questions:
      - Which other service principals does this service principal own?
      - Can I filter owned objects to only service principals?
      instructions:
      - text: List the service principals owned by service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show only owned service principal objects for {sp}.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.servicePrincipal/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count service principals a service principal owns
      effect: read
      questions:
      - How many service principals are owned by one service principal?
      - What is the owned service principal total for an app?
      instructions:
      - text: Count the service principals owned by {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Tell me how many other service principals {sp} owns.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners'].get
  update:
    x-apievangelist-phrasing:
      intent: List the owners of a service principal
      effect: read
      questions:
      - Who are the owners allowed to modify a service principal?
      - Which users and service principals own an enterprise app?
      instructions:
      - text: List the owners of service principal {sp}.
        slots:
          sp: path.servicePrincipal-id
      - text: Show who owns {sp}, with their full directory objects.
        slots:
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/$ref'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove an owner from a service principal by owner id
      effect: destructive
      questions:
      - Can I remove a specific owner from a service principal using the owner's object id?
      - What is the recommended minimum number of owners to keep on a service principal?
      instructions:
      - text: Remove owner {owner} from service principal {sp}.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Take object {owner} off the owners of {sp} using its id in the path.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.appRoleAssignment'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a service principal owner as an app role assignment
      effect: read
      questions:
      - Can I read an owner of a service principal as an app role assignment?
      - Which app role assignment details come back for that type of owner?
      instructions:
      - text: Get owner {owner} of {sp} as an app role assignment.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show the app role assignment owner {owner} on service principal {sp}.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.endpoint'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a service principal owner as an endpoint
      effect: read
      questions:
      - Can I read an owner of a service principal cast as an endpoint?
      - What endpoint properties does an endpoint-type owner of an app have?
      instructions:
      - text: Get owner {owner} of {sp} as an endpoint.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show the endpoint owner {owner} on service principal {sp}.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a service principal owner as a service principal
      effect: read
      questions:
      - Can I read an owner that is itself a service principal with its app properties?
      - Which service principal owns this enterprise app, and what are its details?
      instructions:
      - text: Get owner {owner} of {sp} as a service principal.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Fetch owner {owner} of {sp} with its app identity fields.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.user'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a service principal owner as a user
      effect: read
      questions:
      - Can I read a user owner of a service principal with their user profile fields?
      - What user details come back for a person who owns an enterprise app?
      instructions:
      - text: Get owner {owner} of {sp} as a user.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      - text: Show the user profile of owner {owner} on service principal {sp}.
        slots:
          owner: path.directoryObject-id
          sp: path.servicePrincipal-id
      method: generated
      generated: '2026-10-01'


# --- truncated at 32 KB (49 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/azure-ad/refs/heads/main/overlays/azure-ad-serviceprincipals-directoryobject-api-phrasing-overlay.yaml