Microsoft Active Directory website screenshot

Microsoft Active Directory

Microsoft Active Directory and Microsoft Entra ID provide identity and access management for organizations of all sizes. Microsoft Graph API is the unified REST API gateway for accessing and managing Microsoft Entra ID (formerly Azure Active Directory), including users, groups, applications, devices, conditional access policies, identity governance, and directory administration. Legacy on-premises Active Directory is managed through LDAP, Kerberos, and PowerShell protocols; cloud identity is managed through Microsoft Graph.

Microsoft Active Directory publishes 7 APIs on the APIs.io network, including App Role Assignments API, Applications API, Groups API, and 4 more. Tagged areas include Active Directory, Authentication, Authorization, Directory Services, and Identity Management.

The Microsoft Active Directory catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Microsoft Active Directory’s developer surface includes authentication, developer portal, getting-started guide, documentation, API reference, CLI, engineering blog, and 34 more developer resources.

71.5/100 exemplar ▬ flat Agent 34/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
14 APIs 10 Features 7 Use Cases
Active DirectoryAuthenticationAuthorizationDirectory ServicesIdentity ManagementMicrosoft EntraZero Trust

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 71.5/100 · exemplar
Contract Quality 18.8 / 25
Developer Ergonomics 13.9 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 8.9 / 13
Governance 8.3 / 12
Discoverability 7.4 / 10
Agent readiness — 34/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/active-directory: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 14

Individual APIs this provider publishes, each with its own machine-readable definition.

Microsoft Graph Devices API

Manage devices registered or joined to Microsoft Entra ID, including Entra joined, Entra registered, and hybrid Azure AD joined devices. Retrieve BitLocker recovery keys and Loc...

Microsoft Graph Directory Roles and Administrative Units API

Manage Microsoft Entra built-in and custom directory roles, role assignments, and role-scoped administrative units. Assign administrator roles to users, groups, or service princ...

Microsoft Graph Conditional Access API

Create and manage Microsoft Entra Conditional Access policies that enforce access controls based on user, location, device, and risk signals. Configure named locations, authenti...

Microsoft Graph Identity Governance API

Manage Microsoft Entra ID Governance features including access reviews, entitlement management (access packages, catalogs, and policies), Privileged Identity Management (PIM) fo...

Microsoft Graph Identity Protection API

Detect, investigate, and remediate identity-based risks using Microsoft Entra ID Protection. Access risk detections, risky users, risky service principals, and risk events, and ...

Microsoft Graph Authentication Methods API

Manage authentication methods registered for users in Microsoft Entra ID, including FIDO2 security keys, Microsoft Authenticator, phone (SMS/voice call), email OTP, Windows Hell...

Microsoft Graph Identity and Access Reports API

Access audit logs, sign-in logs, provisioning logs, and identity-related reports for monitoring, compliance, and troubleshooting. Stream logs to Azure Monitor and Log Analytics ...

Microsoft Active Directory App Role Assignments API

The App Role Assignments API from Microsoft Active Directory — 1 operation(s) for app role assignments.

Microsoft Active Directory Applications API

The Applications API from Microsoft Active Directory — 2 operation(s) for applications.

Microsoft Active Directory Groups API

The Groups API from Microsoft Active Directory — 6 operation(s) for groups.

Microsoft Active Directory Members API

The Members API from Microsoft Active Directory — 2 operation(s) for members.

Microsoft Active Directory Owners API

The Owners API from Microsoft Active Directory — 1 operation(s) for owners.

Microsoft Active Directory Service Principals API

The Service Principals API from Microsoft Active Directory — 3 operation(s) for service principals.

Microsoft Active Directory Users API

The Users API from Microsoft Active Directory — 5 operation(s) for users.

Scroll for all 14

Postman Collections 3

Ready-to-run Postman collections for exercising this provider's APIs.

Arazzo Workflows 13

Multi-step API workflows described with the Arazzo specification.

Active Directory Audit User Group Memberships

Resolve a user by UPN, read their full profile, then list their group memberships and manager.

ARAZZO

Active Directory Create Group And Add Two Members

Create a security group, then add two existing users to it by their object IDs.

ARAZZO

Active Directory Create Microsoft 365 Group With Owner

Create a user, create a Microsoft 365 group owned by that user, and add the user as a member.

ARAZZO

Active Directory Decommission Application

Resolve an application by name, read its details, and soft-delete the registration.

ARAZZO

Active Directory Find User And Update Profile

Look up a user by principal name, then patch their job title and department.

ARAZZO

Active Directory Offboard User From Group

Resolve a user by UPN, remove them from a named group, then disable the account.

ARAZZO

Active Directory Onboard User To Existing Group

Find an existing group by name, create a user, and add the user to that group.

ARAZZO

Active Directory Provision Application With Service Principal

Register an application, then locate and read its service principal and app role assignments.

ARAZZO

Active Directory Provision User Into New Group

Create a user, create a security group, and add the user as a member of that group.

ARAZZO

Active Directory Rename Group And List Members

Resolve a group by name, update its display name and description, then list its members and owners.

ARAZZO

Active Directory Self-Service Profile Review

Read the signed-in user's profile, then list their group memberships and look up their manager.

ARAZZO

Active Directory Transfer User Between Groups

Resolve a user and two groups by name, remove the user from one group and add them to another.

ARAZZO

Active Directory Update Application Redirect URIs

Resolve an application by name, read it, then patch its web redirect URIs and description.

ARAZZO

Scroll for all 13

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Active Directory Rate Limits

7 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 10

Notable capabilities this provider offers.

Unified Identity API

Single REST endpoint (graph.microsoft.com) for all Microsoft Entra identity and directory operations.

User Lifecycle Management

Full CRUD operations for user accounts including bulk operations, license assignment, and guest management.

Group Management

Create and manage security groups, Microsoft 365 groups, and dynamic membership groups.

Application Registration

Programmatic app registration, permission configuration, and service principal management.

Conditional Access Automation

Create, update, and evaluate Conditional Access policies via API for Zero Trust enforcement.

Privileged Identity Management

Just-in-time role activation, time-bound access, and PIM policy management via API.

Identity Protection

Access risk signals, risky users, and risk detections for automated threat response.

Authentication Method Management

Manage MFA and passwordless authentication methods registered for users.

Audit and Sign-in Logs

Programmatic access to audit logs, sign-in logs, and provisioning logs for SIEM integration.

Identity Governance

Access reviews, entitlement management, and lifecycle workflows for automated IAM.

Scroll for all 10

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Active Directory Context

1 classes · 69 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Microsoft Active Directory API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Microsoft Active Directory API Rules

39 rules · 14 errors 20 warnings 5 info

SPECTRAL

JSON Schema 5

Standalone JSON Schema definitions for this provider's data models.

Application

12 properties

JSON SCHEMA

ServicePrincipal

12 properties

JSON SCHEMA

Group

18 properties

JSON SCHEMA

PasswordProfile

3 properties

JSON SCHEMA

User

22 properties

JSON SCHEMA

JSON Structure 3

JSON Structure definitions describing this provider's data shapes.

Applications Application Structure

0 properties

JSON STRUCTURE

Groups Group Structure

0 properties

JSON STRUCTURE

Users User Structure

0 properties

JSON STRUCTURE

Examples 3

Example request and response payloads for these APIs.

Groups Group Example

17 fields

EXAMPLE

Users User Example

22 fields

EXAMPLE

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Active Directory Authentication

oauth2 · 1 scheme

SECURITY

Active Directory Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Active Directory Vulnerability Disclosure

security.txt · contact published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Active Directory Scopes

11 scopes · authorizationCode/clientCredentials

11 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Active Directory Agentic Access

25 operations · 11 acting

25 operations · 11 acting

AGENTIC

Use Cases 7

What developers build with this provider.

User Provisioning Automation

Automate user account creation, attribute updates, and deprovisioning for HR-driven identity lifecycle.

Zero Trust Policy Enforcement

Programmatically deploy and manage Conditional Access policies across the organization.

SIEM Integration

Stream audit logs and sign-in events to security information and event management systems.

Application Access Management

Automate app registration, permission grants, and app role assignments for developer self-service.

Identity Risk Remediation

Detect and respond to risky sign-ins and compromised accounts via Identity Protection APIs.

Compliance Reporting

Generate access reviews, entitlement reports, and audit logs for regulatory compliance.

Privileged Access Governance

Enforce just-in-time privileged access and audit role assignments via PIM APIs.

Scroll for all 7

Integrations 7

Pre-built integrations with other platforms and tools.

Azure Active Directory

Microsoft Entra ID (formerly Azure AD) is the cloud identity backbone accessed via Microsoft Graph.

Microsoft 365

Microsoft Graph provides unified access to Microsoft 365 user data alongside identity operations.

Azure Monitor

Stream Microsoft Entra sign-in and audit logs to Azure Monitor Log Analytics for analysis.

Microsoft Sentinel

Feed identity risk signals and audit logs into Microsoft Sentinel SIEM for threat hunting.

Intune

Microsoft Graph Intune APIs integrate device management with identity policies.

SCIM Providers

Automate user provisioning to SaaS applications using Microsoft Entra SCIM provisioning.

SAML and OIDC Applications

Register and manage federated applications using SAML 2.0 and OpenID Connect via Microsoft Graph.

Scroll for all 7

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 16

Pagination, idempotency, versioning, errors, and events

Scroll for all 16

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 5

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
name: Microsoft Active Directory
description: Microsoft Active Directory and Microsoft Entra ID provide identity and access management for organizations of
  all sizes. Microsoft Graph API is the unified REST API gateway for accessing and managing Microsoft Entra ID (formerly Azure
  Active Directory), including users, groups, applications, devices, conditional access policies, identity governance, and
  directory administration. Legacy on-premises Active Directory is managed through LDAP, Kerberos, and PowerShell protocols;
  cloud identity is managed through Microsoft Graph.
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://learn.microsoft.com/en-us/entra/media/index/active-directory.svg
created: '2024-01-01'
modified: '2026-05-19'
specificationVersion: '0.19'
tags:
- Active Directory
- Authentication
- Authorization
- Directory Services
- Identity Management
- Microsoft Entra
- Zero Trust
apis:
- name: Microsoft Graph Devices API
  description: Manage devices registered or joined to Microsoft Entra ID, including Entra joined, Entra registered, and hybrid
    Azure AD joined devices. Retrieve BitLocker recovery keys and Local Admin Password Solution (LAPS) credentials for managed
    devices.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/device
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Devices
  - Endpoint Management
  - Identity Management
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/device
- name: Microsoft Graph Directory Roles and Administrative Units API
  description: Manage Microsoft Entra built-in and custom directory roles, role assignments, and role-scoped administrative
    units. Assign administrator roles to users, groups, or service principals, and create scoped role assignments via administrative
    units.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/directoryrole
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Authorization
  - Directory Services
  - Role Management
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/directoryrole
- name: Microsoft Graph Conditional Access API
  description: Create and manage Microsoft Entra Conditional Access policies that enforce access controls based on user, location,
    device, and risk signals. Configure named locations, authentication context class references, and evaluate policy impact
    using what-if analysis.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Authorization
  - Conditional Access
  - Security
  - Zero Trust
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy
- name: Microsoft Graph Identity Governance API
  description: Manage Microsoft Entra ID Governance features including access reviews, entitlement management (access packages,
    catalogs, and policies), Privileged Identity Management (PIM) for just-in-time role activation, and lifecycle workflows
    for joiner/mover/leaver employee identity lifecycle automation.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Governance
  - Identity Management
  - Lifecycle Management
  - Privileged Identity Management
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview
- name: Microsoft Graph Identity Protection API
  description: Detect, investigate, and remediate identity-based risks using Microsoft Entra ID Protection. Access risk detections,
    risky users, risky service principals, and risk events, and feed data into SIEM tools for security correlation and incident
    response.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/identityprotection-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Identity Protection
  - Risk Management
  - Security
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identityprotection-overview
- name: Microsoft Graph Authentication Methods API
  description: Manage authentication methods registered for users in Microsoft Entra ID, including FIDO2 security keys, Microsoft
    Authenticator, phone (SMS/voice call), email OTP, Windows Hello for Business, and temporary access passes. Configure authentication
    method policies and authentication strength requirements.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethods-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Authentication
  - MFA
  - Passwordless
  - Security
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethods-overview
- name: Microsoft Graph Identity and Access Reports API
  description: Access audit logs, sign-in logs, provisioning logs, and identity-related reports for monitoring, compliance,
    and troubleshooting. Stream logs to Azure Monitor and Log Analytics or to third-party SIEM tools for security operations.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/report-identity-access
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Audit Logs
  - Compliance
  - Monitoring
  - Reports
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/report-identity-access
- aid: active-directory:active-directory-app-role-assignments-api
  name: Microsoft Active Directory App Role Assignments API
  description: The App Role Assignments API from Microsoft Active Directory — 1 operation(s) for app role assignments.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - App Role Assignments
  properties:
  - type: OpenAPI
    url: openapi/active-directory-app-role-assignments-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
- aid: active-directory:active-directory-applications-api
  name: Microsoft Active Directory Applications API
  description: The Applications API from Microsoft Active Directory — 2 operation(s) for applications.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Applications
  properties:
  - type: OpenAPI
    url: openapi/active-directory-applications-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
- aid: active-directory:active-directory-groups-api
  name: Microsoft Active Directory Groups API
  description: The Groups API from Microsoft Active Directory — 6 operation(s) for groups.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Groups
  properties:
  - type: OpenAPI
    url: openapi/active-directory-groups-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
- aid: active-directory:active-directory-members-api
  name: Microsoft Active Directory Members API
  description: The Members API from Microsoft Active Directory — 2 operation(s) for members.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Members
  properties:
  - type: OpenAPI
    url: openapi/active-directory-members-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
- aid: active-directory:active-directory-owners-api
  name: Microsoft Active Directory Owners API
  description: The Owners API from Microsoft Active Directory — 1 operation(s) for owners.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Owners
  properties:
  - type: OpenAPI
    url: openapi/active-directory-owners-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
- aid: active-directory:active-directory-service-principals-api
  name: Microsoft Active Directory Service Principals API
  description: The Service Principals API from Microsoft Active Directory — 3 operation(s) for service principals.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Service Principals
  properties:
  - type: OpenAPI
    url: openapi/active-directory-service-principals-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
- aid: active-directory:active-directory-users-api
  name: Microsoft Active Directory Users API
  description: The Users API from Microsoft Active Directory — 5 operation(s) for users.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/users
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Users
  properties:
  - type: OpenAPI
    url: openapi/active-directory-users-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/users
  - type: JSONSchema
    url: json-schema/users-user-schema.json
  - type: JSONSchema
    url: json-schema/users-password-profile-schema.json
  - type: JSONStructure
    url: json-structure/users-user-structure.json
  - type: Examples
    url: examples/users-user-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/groups-overview
  - type: JSONSchema
    url: json-schema/groups-group-schema.json
  - type: JSONStructure
    url: json-structure/groups-group-structure.json
  - type: Examples
    url: examples/groups-group-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: JSONSchema
    url: json-schema/applications-application-schema.json
  - type: JSONSchema
    url: json-schema/applications-service-principal-schema.json
  - type: JSONStructure
    url: json-structure/applications-application-structure.json
  - type: Examples
    url: examples/applications-application-example.json
common:
- type: AgenticAccess
  url: agentic-access/active-directory-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/active-directory-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/active-directory-domain-security.yml
- type: Authentication
  url: authentication/active-directory-authentication.yml
- type: OAuthScopes
  url: scopes/active-directory-scopes.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/microsoft-active-directory/overview
- type: Arazzo
  url: arazzo/active-directory-audit-user-group-memberships-workflow.yml
  name: Active Directory Audit User Group Memberships
- type: Arazzo
  url: arazzo/active-directory-create-group-and-add-members-workflow.yml
  name: Active Directory Create Group And Add Two Members
- type: Arazzo
  url: arazzo/active-directory-create-m365-group-with-owner-workflow.yml
  name: Active Directory Create Microsoft 365 Group With Owner
- type: Arazzo
  url: arazzo/active-directory-decommission-application-workflow.yml
  name: Active Directory Decommission Application
- type: Arazzo
  url: arazzo/active-directory-find-user-and-update-profile-workflow.yml
  name: Active Directory Find User And Update Profile
- type: Arazzo
  url: arazzo/active-directory-offboard-user-from-group-workflow.yml
  name: Active Directory Offboard User From Group
- type: Arazzo
  url: arazzo/active-directory-onboard-user-to-existing-group-workflow.yml
  name: Active Directory Onboard User To Existing Group
- type: Arazzo
  url: arazzo/active-directory-provision-application-with-membership-workflow.yml
  name: Active Directory Provision Application With Service Principal
- type: Arazzo
  url: arazzo/active-directory-provision-user-into-new-group-workflow.yml
  name: Active Directory Provision User Into New Group
- type: Arazzo
  url: arazzo/active-directory-rename-group-and-list-members-workflow.yml
  name: Active Directory Rename Group And List Members
- type: Arazzo
  url: arazzo/active-directory-self-service-profile-review-workflow.yml
  name: Active Directory Self-Service Profile Review
- type: Arazzo
  url: arazzo/active-directory-transfer-user-between-groups-workflow.yml
  name: Active Directory Transfer User Between Groups
- type: Arazzo
  url: arazzo/active-directory-update-application-redirect-uris-workflow.yml
  name: Active Directory Update Application Redirect URIs
- type: Portal
  url: https://developer.microsoft.com/en-us/graph
- type: GettingStarted
  url: https://learn.microsoft.com/en-us/graph/get-started
- type: Documentation
  url: https://learn.microsoft.com/en-us/graph/overview
- type: Authentication
  url: https://learn.microsoft.com/en-us/graph/auth/auth-concepts
- type: APIReference
  url: https://learn.microsoft.com/en-us/graph/api/overview
- type: RateLimits
  url: https://learn.microsoft.com/en-us/graph/throttling
- type: SDKs
  url: https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
- type: CLI
  url: https://learn.microsoft.com/en-us/cli/azure/ad
- type: Blog
  url: https://devblogs.microsoft.com/microsoft365dev/
- type: StatusPage
  url: https://azure.status.microsoft.com/
- type: Support
  url: https://developer.microsoft.com/en-us/graph/support
- type: TermsOfService
  url: https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use
- type: PrivacyPolicy
  url: https://privacy.microsoft.com/privacystatement
- type: Pricing
  url: https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing
- type: ChangeLog
  url: https://learn.microsoft.com/en-us/graph/changelog
- type: GitHubOrganization
  url: https://github.com/microsoftgraph
- type: GitHubRepository
  url: https://github.com/microsoftgraph/microsoft-graph-openapi
- type: StackOverflow
  url: https://stackoverflow.com/questions/tagged/microsoft-graph
- type: Training
  url: https://learn.microsoft.com/en-us/training/paths/m365-msgraph-associate/
- type: SpectralRules
  url: rules/active-directory-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/active-directory-vocabulary.yaml
- type: JSONLD
  url: json-ld/active-directory-context.jsonld
- type: Features
  data:
  - name: Unified Identity API
    description: Single REST endpoint (graph.microsoft.com) for all Microsoft Entra identity and directory operations.
  - name: User Lifecycle Management
    description: Full CRUD operations for user accounts including bulk operations, license assignment, and guest management.
  - name: Group Management
    description: Create and manage security groups, Microsoft 365 groups, and dynamic membership groups.
  - name: Application Registration
    description: Programmatic app registration, permission configuration, and service principal management.
  - name: Conditional Access Automation
    description: Create, update, and evaluate Conditional Access policies via API for Zero Trust enforcement.
  - name: Privileged Identity Management
    description: Just-in-time role activation, time-bound access, and PIM policy management via API.
  - name: Identity Protection
    description: Access risk signals, risky users, and risk detections for automated threat response.
  - name: Authentication Method Management
    description: Manage MFA and passwordless authentication methods registered for users.
  - name: Audit and Sign-in Logs
    description: Programmatic access to audit logs, sign-in logs, and provisioning logs for SIEM integration.
  - name: Identity Governance
    description: Access reviews, entitlement management, and lifecycle workflows for automated IAM.
- type: UseCases
  data:
  - name: User Provisioning Automation
    description: Automate user account creation, attribute updates, and deprovisioning for HR-driven identity lifecycle.
  - name: Zero Trust Policy Enforcement
    description: Programmatically deploy and manage Conditional Access policies across the organization.
  - name: SIEM Integration
    description: Stream audit logs and sign-in events to security information and event management systems.
  - name: Application Access Management
    description: Automate app registration, permission grants, and app role assignments for developer self-service.
  - name: Identity Risk Remediation
    description: Detect and respond to risky sign-ins and compromised accounts via Identity Protection APIs.
  - name: Compliance Reporting
    description: Generate access reviews, entitlement reports, and audit logs for regulatory compliance.
  - name: Privileged Access Governance
    description: Enforce just-in-time privileged access and audit role assignments via PIM APIs.
- type: Integrations
  data:
  - name: Azure Active Directory
    description: Microsoft Entra ID (formerly Azure AD) is the cloud identity backbone accessed via Microsoft Graph.
  - name: Microsoft 365
    description: Microsoft Graph provides unified access to Microsoft 365 user data alongside identity operations.
  - name: Azure Monitor
    description: Stream Microsoft Entra sign-in and audit logs to Azure Monitor Log Analytics for analysis.
  - name: Microsoft Sentinel
    description: Feed identity risk signals and audit logs into Microsoft Sentinel SIEM for threat hunting.
  - name: Intune
    description: Microsoft Graph Intune APIs integrate device management with identity policies.
  - name: SCIM Providers
    description: Automate user provisioning to SaaS applications using Microsoft Entra SCIM provisioning.
  - name: SAML and OIDC Applications
    description: Register and manage federated applications using SAML 2.0 and OpenID Connect via Microsoft Graph.
maintainers:
- name: Kin Lane
  email: kin@apievangelist.com