# Microsoft Active Directory

**Canonical:** https://apis.io/providers/active-directory/  
**Website:** https://developer.microsoft.com/en-us/graph  
**APIs profiled:** 14

Microsoft Active Directory and Microsoft Entra ID provide identity and access management for organizations of all sizes. Microsoft Graph API is the unified REST API gateway for accessing and managing Microsoft Entra ID (formerly Azure Active Directory), including users, groups, applications, devices, conditional access policies, identity governance, and directory administration. Legacy on-premises Active Directory is managed through LDAP, Kerberos, and PowerShell protocols; cloud identity is managed through Microsoft Graph.

## Kin Score — 54.4 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 54.4).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 77.0 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 18.4 |
| Developer Ergonomics | 64.3 |
| Commercial Clarity | 47.4 |
| Access Clarity | 47.4 |

## Agent readiness — 32.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (14)

- **Microsoft Graph Devices API** — Manage devices registered or joined to Microsoft Entra ID, including Entra joined, Entra registered, and hybrid Azure AD joined devices. Retrieve BitLocker recovery keys and Loc...
- **Microsoft Graph Directory Roles and Administrative Units API** — Manage Microsoft Entra built-in and custom directory roles, role assignments, and role-scoped administrative units. Assign administrator roles to users, groups, or service princ...
- **Microsoft Graph Conditional Access API** — Create and manage Microsoft Entra Conditional Access policies that enforce access controls based on user, location, device, and risk signals. Configure named locations, authenti...
- **Microsoft Graph Identity Governance API** — Manage Microsoft Entra ID Governance features including access reviews, entitlement management (access packages, catalogs, and policies), Privileged Identity Management (PIM) fo...
- **Microsoft Graph Identity Protection API** — Detect, investigate, and remediate identity-based risks using Microsoft Entra ID Protection. Access risk detections, risky users, risky service principals, and risk events, and ...
- **Microsoft Graph Authentication Methods API** — Manage authentication methods registered for users in Microsoft Entra ID, including FIDO2 security keys, Microsoft Authenticator, phone (SMS/voice call), email OTP, Windows Hell...
- **Microsoft Graph Identity and Access Reports API** — Access audit logs, sign-in logs, provisioning logs, and identity-related reports for monitoring, compliance, and troubleshooting. Stream logs to Azure Monitor and Log Analytics ...
- **Microsoft Active Directory App Role Assignments API** — The App Role Assignments API from Microsoft Active Directory — 1 operation(s) for app role assignments.
- **Microsoft Active Directory Applications API** — The Applications API from Microsoft Active Directory — 2 operation(s) for applications.
- **Microsoft Active Directory Groups API** — The Groups API from Microsoft Active Directory — 6 operation(s) for groups.
- **Microsoft Active Directory Members API** — The Members API from Microsoft Active Directory — 2 operation(s) for members.
- **Microsoft Active Directory Owners API** — The Owners API from Microsoft Active Directory — 1 operation(s) for owners.
- **Microsoft Active Directory Service Principals API** — The Service Principals API from Microsoft Active Directory — 3 operation(s) for service principals.
- **Microsoft Active Directory Users API** — The Users API from Microsoft Active Directory — 5 operation(s) for users.

## Agentic access (1)

- **Active Directory Agentic Access** — 25 operations · 11 acting

## Security (3)

- **Active Directory Authentication** — oauth2 · 1 scheme
- **Active Directory Domain Security** — TLSv1.3 · HSTS · DMARC
- **Active Directory Vulnerability Disclosure** — security.txt · contact published

## Plans (1)

- **Active Directory Plans Pricing**

## Use cases (7)

- **User Provisioning Automation** — Automate user account creation, attribute updates, and deprovisioning for HR-driven identity lifecycle.
- **Zero Trust Policy Enforcement** — Programmatically deploy and manage Conditional Access policies across the organization.
- **SIEM Integration** — Stream audit logs and sign-in events to security information and event management systems.
- **Application Access Management** — Automate app registration, permission grants, and app role assignments for developer self-service.
- **Identity Risk Remediation** — Detect and respond to risky sign-ins and compromised accounts via Identity Protection APIs.
- **Compliance Reporting** — Generate access reviews, entitlement reports, and audit logs for regulatory compliance.
- **Privileged Access Governance** — Enforce just-in-time privileged access and audit role assignments via PIM APIs.

## Tags

Active Directory, Authentication, Authorization, Directory Services, Identity Management, Microsoft Entra, Zero Trust

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/active-directory/). Scores are computed from the provider's own public artifacts under a published rubric.
