Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Applications Service Principals.directory Object API
67 actions
67 updates
phrasing
extends
openapi/azure-ad-serviceprincipals-directoryobject-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
What the actions change
x-apievangelist-phrasing
Targets 67 · first 16 shown; the file carries all of them
$.info
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.administrativeUnit'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.directoryRole'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.group'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit/$count'].get
$.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Applications Service Principals.directory Object API
version: 1.0.0
extends: openapi/azure-ad-serviceprincipals-directoryobject-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 66
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects'].get
update:
x-apievangelist-phrasing:
intent: List objects a service principal created
effect: read
questions:
- Which directory objects were created by a particular service principal?
- Can I see everything an app's service principal has created in my tenant?
instructions:
- text: List all directory objects created by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show the first {top} objects that service principal {sp} created.
slots:
top: query.$top
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}'].get
update:
x-apievangelist-phrasing:
intent: Get one object a service principal created
effect: read
questions:
- What are the details of a single object that a service principal created?
- Can I look up one specific created object by its id under its creating service principal?
instructions:
- text: Get created object {object} from service principal {sp}.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show me the directory object {object} that {sp} created.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
update:
x-apievangelist-phrasing:
intent: Get a created object typed as a service principal
effect: read
questions:
- Can I read a created object with its service principal properties rather than generic directory fields?
- Is the object a service principal created itself a service principal, and what are its app details?
instructions:
- text: Get created object {object} of service principal {sp}, cast as a service principal.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Return created item {object} under {sp} with its full service principal fields.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/$count'].get
update:
x-apievangelist-phrasing:
intent: Count objects a service principal created
effect: read
questions:
- How many directory objects has a given service principal created?
- Is there a quick way to get just the total of created objects for an app without listing them?
instructions:
- text: Count the directory objects created by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Give me the number of created objects for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal'].get
update:
x-apievangelist-phrasing:
intent: List service principals a service principal created
effect: read
questions:
- Which service principals were created by another service principal?
- Can I filter a service principal's created objects down to only service principals?
instructions:
- text: List only the service principals that {sp} created.
slots:
sp: path.servicePrincipal-id
- text: Show created objects of {sp} that are service principals, first {top}.
slots:
sp: path.servicePrincipal-id
top: query.$top
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal/$count'].get
update:
x-apievangelist-phrasing:
intent: Count service principals a service principal created
effect: read
questions:
- How many service principals has one service principal created?
- What is the total of created objects that are themselves service principals?
instructions:
- text: Count the service principals created by {sp}.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many of the objects {sp} created are service principals.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf'].get
update:
x-apievangelist-phrasing:
intent: List a service principal's direct memberships
effect: read
questions:
- Which groups and directory roles is a service principal directly a member of?
- Does the memberOf list for an app include nested group memberships?
instructions:
- text: List the groups and roles service principal {sp} directly belongs to.
slots:
sp: path.servicePrincipal-id
- text: Show the direct, non-transitive memberships of {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}'].get
update:
x-apievangelist-phrasing:
intent: Get one direct membership of a service principal
effect: read
questions:
- Can I fetch a single group or role that a service principal is directly a member of?
- What does one direct membership entry for a service principal look like?
instructions:
- text: Get direct membership {object} of service principal {sp}.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show the group or role {object} that {sp} is directly a member of.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.administrativeUnit'].get
update:
x-apievangelist-phrasing:
intent: Get a direct membership as an administrative unit
effect: read
questions:
- Can I read one of a service principal's direct memberships as an administrative unit?
- What are the admin unit details for a unit a service principal directly belongs to?
instructions:
- text: Get direct membership {unit} of {sp} as an administrative unit.
slots:
unit: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show administrative unit {unit} that service principal {sp} is directly in.
slots:
unit: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.directoryRole'].get
update:
x-apievangelist-phrasing:
intent: Get a direct membership as a directory role
effect: read
questions:
- Can I read one of a service principal's direct memberships as a directory role?
- Which role details come back for a role a service principal holds directly?
instructions:
- text: Get direct membership {role} of {sp} as a directory role.
slots:
role: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show directory role {role} that service principal {sp} directly holds.
slots:
role: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.group'].get
update:
x-apievangelist-phrasing:
intent: Get a direct membership as a group
effect: read
questions:
- Can I read one of a service principal's direct memberships with its group properties?
- What are the group details for a group an app is directly a member of?
instructions:
- text: Get direct membership {group} of {sp} as a group.
slots:
group: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show group {group} that service principal {sp} is directly a member of.
slots:
group: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/$count'].get
update:
x-apievangelist-phrasing:
intent: Count a service principal's direct memberships
effect: read
questions:
- How many groups and roles is a service principal directly a member of?
- What is the total of direct memberships for one app?
instructions:
- text: Count the direct memberships of service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Give me the number of groups and roles {sp} directly belongs to.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit'].get
update:
x-apievangelist-phrasing:
intent: List admin units a service principal is directly in
effect: read
questions:
- Which administrative units is a service principal directly a member of?
- Can I narrow a service principal's direct memberships to administrative units only?
instructions:
- text: List the administrative units {sp} is directly a member of.
slots:
sp: path.servicePrincipal-id
- text: Show only admin-unit memberships held directly by service principal {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit/$count'].get
update:
x-apievangelist-phrasing:
intent: Count admin units a service principal is directly in
effect: read
questions:
- How many administrative units does a service principal directly belong to?
- What is the count of direct admin-unit memberships for an app?
instructions:
- text: Count the administrative units {sp} is directly in.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many admin units service principal {sp} directly belongs to.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole'].get
update:
x-apievangelist-phrasing:
intent: List directory roles a service principal holds directly
effect: read
questions:
- Which directory roles has a service principal been directly assigned?
- Can I list only the roles, not groups, that an app is directly a member of?
instructions:
- text: List the directory roles service principal {sp} holds directly.
slots:
sp: path.servicePrincipal-id
- text: Show only direct directory-role memberships for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole/$count'].get
update:
x-apievangelist-phrasing:
intent: Count directory roles a service principal holds directly
effect: read
questions:
- How many directory roles does a service principal directly hold?
- What is the number of direct role memberships for an app?
instructions:
- text: Count the directory roles {sp} directly holds.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many roles service principal {sp} is directly assigned.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.group'].get
update:
x-apievangelist-phrasing:
intent: List groups a service principal is directly in
effect: read
questions:
- Which groups is a service principal directly a member of?
- Can I see only the direct group memberships of an app, without roles?
instructions:
- text: List the groups service principal {sp} is directly a member of.
slots:
sp: path.servicePrincipal-id
- text: Show only direct group memberships for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.group/$count'].get
update:
x-apievangelist-phrasing:
intent: Count groups a service principal is directly in
effect: read
questions:
- How many groups is a service principal directly a member of?
- What is the direct group membership total for an app?
instructions:
- text: Count the groups {sp} is directly in.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many groups service principal {sp} directly belongs to.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects'].get
update:
x-apievangelist-phrasing:
intent: List objects a service principal owns
effect: read
questions:
- Which applications, groups or other objects does a service principal own?
- Can I get every directory object owned by an app's service principal?
instructions:
- text: List all objects owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show the first {top} directory objects that {sp} owns.
slots:
top: query.$top
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}'].get
update:
x-apievangelist-phrasing:
intent: Get one object a service principal owns
effect: read
questions:
- Can I fetch a single owned object by id for a service principal?
- What are the generic directory details of one object an app owns?
instructions:
- text: Get owned object {object} of service principal {sp}.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show the directory object {object} that {sp} owns.
slots:
object: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.application'].get
update:
x-apievangelist-phrasing:
intent: Get an owned object as an application
effect: read
questions:
- Can I read an object a service principal owns with its application registration properties?
- What app registration details come back for an application owned by a service principal?
instructions:
- text: Get owned object {app} of {sp} as an application.
slots:
app: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show application {app} that service principal {sp} owns.
slots:
app: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.appRoleAssignment'].get
update:
x-apievangelist-phrasing:
intent: Get an owned object as an app role assignment
effect: read
questions:
- Can I read an owned object of a service principal as an app role assignment?
- Which role and principal does an app role assignment owned by a service principal point to?
instructions:
- text: Get owned object {assignment} of {sp} as an app role assignment.
slots:
assignment: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show app role assignment {assignment} owned by service principal {sp}.
slots:
assignment: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.endpoint'].get
update:
x-apievangelist-phrasing:
intent: Get an owned object as an endpoint
effect: read
questions:
- Can I read an owned object of a service principal as an endpoint?
- What endpoint details are returned for one endpoint a service principal owns?
instructions:
- text: Get owned object {endpoint} of {sp} as an endpoint.
slots:
endpoint: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show endpoint {endpoint} owned by service principal {sp}.
slots:
endpoint: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.group'].get
update:
x-apievangelist-phrasing:
intent: Get an owned object as a group
effect: read
questions:
- Can I read a group that a service principal owns with its group properties?
- What group details come back for one group owned by an app?
instructions:
- text: Get owned object {group} of {sp} as a group.
slots:
group: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show group {group} that service principal {sp} owns.
slots:
group: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
update:
x-apievangelist-phrasing:
intent: Get an owned object as a service principal
effect: read
questions:
- Can I read another service principal that this service principal owns?
- What app details come back for a service principal owned by a different one?
instructions:
- text: Get owned object {owned} of {sp} as a service principal.
slots:
owned: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show service principal {owned} that is owned by service principal {sp}.
slots:
owned: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/$count'].get
update:
x-apievangelist-phrasing:
intent: Count objects a service principal owns
effect: read
questions:
- How many directory objects does a service principal own in total?
- What is the owned-object count for one app?
instructions:
- text: Count all objects owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Give me the total number of owned objects for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.application'].get
update:
x-apievangelist-phrasing:
intent: List applications a service principal owns
effect: read
questions:
- Which application registrations does a service principal own?
- Can I narrow a service principal's owned objects to applications only?
instructions:
- text: List the applications owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show only application registrations that {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.application/$count'].get
update:
x-apievangelist-phrasing:
intent: Count applications a service principal owns
effect: read
questions:
- How many application registrations does a service principal own?
- What is the number of apps owned by one service principal?
instructions:
- text: Count the applications owned by {sp}.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many app registrations service principal {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.appRoleAssignment'].get
update:
x-apievangelist-phrasing:
intent: List app role assignments a service principal owns
effect: read
questions:
- Which app role assignments are owned by a service principal?
- Can I filter a service principal's owned objects to app role assignments?
instructions:
- text: List the app role assignments owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show only owned app role assignments for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.appRoleAssignment/$count'].get
update:
x-apievangelist-phrasing:
intent: Count app role assignments a service principal owns
effect: read
questions:
- How many app role assignments does a service principal own?
- What is the owned app role assignment total for an app?
instructions:
- text: Count the app role assignments owned by {sp}.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many app role assignments service principal {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.endpoint'].get
update:
x-apievangelist-phrasing:
intent: List endpoints a service principal owns
effect: read
questions:
- Which endpoints does a service principal own?
- Can I see just the endpoint objects owned by an app's service principal?
instructions:
- text: List the endpoints owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show only owned endpoint objects for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.endpoint/$count'].get
update:
x-apievangelist-phrasing:
intent: Count endpoints a service principal owns
effect: read
questions:
- How many endpoints does a service principal own?
- What is the owned endpoint total for one app?
instructions:
- text: Count the endpoints owned by {sp}.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many endpoint objects service principal {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.group'].get
update:
x-apievangelist-phrasing:
intent: List groups a service principal owns
effect: read
questions:
- Which groups are owned by a service principal?
- Can I narrow an app's owned objects to groups only?
instructions:
- text: List the groups owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show only the groups that {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.group/$count'].get
update:
x-apievangelist-phrasing:
intent: Count groups a service principal owns
effect: read
questions:
- How many groups does a service principal own?
- What is the number of groups owned by one app?
instructions:
- text: Count the groups owned by {sp}.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many groups service principal {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.servicePrincipal'].get
update:
x-apievangelist-phrasing:
intent: List service principals a service principal owns
effect: read
questions:
- Which other service principals does this service principal own?
- Can I filter owned objects to only service principals?
instructions:
- text: List the service principals owned by service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show only owned service principal objects for {sp}.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.servicePrincipal/$count'].get
update:
x-apievangelist-phrasing:
intent: Count service principals a service principal owns
effect: read
questions:
- How many service principals are owned by one service principal?
- What is the owned service principal total for an app?
instructions:
- text: Count the service principals owned by {sp}.
slots:
sp: path.servicePrincipal-id
- text: Tell me how many other service principals {sp} owns.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners'].get
update:
x-apievangelist-phrasing:
intent: List the owners of a service principal
effect: read
questions:
- Who are the owners allowed to modify a service principal?
- Which users and service principals own an enterprise app?
instructions:
- text: List the owners of service principal {sp}.
slots:
sp: path.servicePrincipal-id
- text: Show who owns {sp}, with their full directory objects.
slots:
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/$ref'].delete
update:
x-apievangelist-phrasing:
intent: Remove an owner from a service principal by owner id
effect: destructive
questions:
- Can I remove a specific owner from a service principal using the owner's object id?
- What is the recommended minimum number of owners to keep on a service principal?
instructions:
- text: Remove owner {owner} from service principal {sp}.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Take object {owner} off the owners of {sp} using its id in the path.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.appRoleAssignment'].get
update:
x-apievangelist-phrasing:
intent: Get a service principal owner as an app role assignment
effect: read
questions:
- Can I read an owner of a service principal as an app role assignment?
- Which app role assignment details come back for that type of owner?
instructions:
- text: Get owner {owner} of {sp} as an app role assignment.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show the app role assignment owner {owner} on service principal {sp}.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.endpoint'].get
update:
x-apievangelist-phrasing:
intent: Get a service principal owner as an endpoint
effect: read
questions:
- Can I read an owner of a service principal cast as an endpoint?
- What endpoint properties does an endpoint-type owner of an app have?
instructions:
- text: Get owner {owner} of {sp} as an endpoint.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show the endpoint owner {owner} on service principal {sp}.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.servicePrincipal'].get
update:
x-apievangelist-phrasing:
intent: Get a service principal owner as a service principal
effect: read
questions:
- Can I read an owner that is itself a service principal with its app properties?
- Which service principal owns this enterprise app, and what are its details?
instructions:
- text: Get owner {owner} of {sp} as a service principal.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Fetch owner {owner} of {sp} with its app identity fields.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
- target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.user'].get
update:
x-apievangelist-phrasing:
intent: Get a service principal owner as a user
effect: read
questions:
- Can I read a user owner of a service principal with their user profile fields?
- What user details come back for a person who owns an enterprise app?
instructions:
- text: Get owner {owner} of {sp} as a user.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
- text: Show the user profile of owner {owner} on service principal {sp}.
slots:
owner: path.directoryObject-id
sp: path.servicePrincipal-id
method: generated
generated: '2026-10-01'
# --- truncated at 32 KB (49 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/azure-ad/refs/heads/main/overlays/azure-ad-serviceprincipals-directoryobject-api-phrasing-overlay.yaml