Microsoft Azure Active Directory website screenshot

Microsoft Azure Active Directory

Microsoft Azure Active Directory (Azure AD), now Microsoft Entra ID, is Microsoft's cloud-based identity and access management service, which helps employees sign in and access resources.

Microsoft Azure Active Directory publishes 4 APIs on the APIs.io network, including Applications API, Groups API, Service Principals API, and 1 more. Tagged areas include Authentication, Authorization, Identity, Microsoft, and Microsoft Entra.

The Microsoft Azure Active Directory catalog on APIs.io includes 2 JSON-LD contexts and 3 Spectral governance rulesets.

Microsoft Azure Active Directory’s developer surface includes authentication, developer portal, support, engineering blog, pricing, training material, release notes, and 16 more developer resources.

57.4/100 strong ▬ flat Agent 40/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
12 APIs 7 Features 5 Use Cases
AuthenticationAuthorizationIdentityMicrosoftMicrosoft EntraOAuthOpenID ConnectSAMLSCIMSingle Sign-OnZero Trust

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 57.4/100 · strong
Contract Quality 17.9 / 25
Developer Ergonomics 8.3 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 8.9 / 13
Governance 2.5 / 12
Discoverability 5.6 / 10
Agent readiness — 40/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/microsoft-azure-active-directory: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 12

Individual APIs this provider publishes, each with its own machine-readable definition.

Azure AD Graph API (Deprecated)

Legacy API for accessing Azure AD (deprecated in favor of Microsoft Graph).

Azure AD Authentication Library (ADAL)

Authentication library for Azure AD (being replaced by MSAL).

Microsoft Authentication Library (MSAL)

Modern authentication library for Microsoft identity platform.

Microsoft Identity Platform

The Microsoft identity platform provides authentication and authorization services using standards-compliant implementations of OAuth 2.0 and OpenID Connect, enabling developers...

Microsoft Entra Verified ID API

Microsoft Entra Verified ID is a managed verifiable credentials service that enables organizations to issue, manage, and verify decentralized identity credentials based on W3C s...

Microsoft Entra ID Governance API

Microsoft Entra ID Governance APIs in Microsoft Graph enable automated access reviews, entitlement management, lifecycle workflows, and privileged identity management for identi...

Microsoft Entra SCIM Provisioning API

Microsoft Entra ID supports SCIM 2.0 protocol for automatic user and group provisioning to cloud applications, enabling automated identity lifecycle management through standardi...

Microsoft Entra PowerShell

The Microsoft Entra PowerShell module provides cmdlets for managing Microsoft Entra resources programmatically, built on the Microsoft Graph PowerShell SDK.

Microsoft Azure Active Directory Applications API

Manage application registrations in Azure Active Directory. An application object is the global representation of an application across all tenants, defining the app identity, a...

Microsoft Azure Active Directory Groups API

Manage groups in Azure Active Directory. Groups can be security groups, Microsoft 365 groups, or mail-enabled security groups. They provide shared access to resources for a coll...

Microsoft Azure Active Directory Service Principals API

Manage service principals in Azure Active Directory. A service principal is the local representation of an application in a specific tenant. It defines what the application can ...

Microsoft Azure Active Directory Users API

Manage user accounts in Azure Active Directory. Users are the core identity objects representing people in an organization. Each user has a profile with attributes such as displ...

Scroll for all 12

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Pricing Plans 2

Published pricing tiers and plan structures.

Rate Limits 2

Documented rate limits and quota policies.

FinOps 2

Cost, billing, and metering signals for API financial operations.

Features 7

Notable capabilities this provider offers.

Single Sign-On

Enable users to sign in once and access all connected applications without re-authenticating.

Conditional Access

Enforce granular access policies based on user, device, location, and risk signals for zero trust security.

Multi-Factor Authentication

Add a second layer of security with phone, app, or hardware token verification for identity protection.

SCIM User Provisioning

Automate user and group lifecycle management across cloud applications using SCIM 2.0 standard.

Verifiable Credentials

Issue and verify decentralized identity credentials based on W3C standards for privacy-preserving identity verification.

Identity Governance

Automate access reviews, entitlement management, and lifecycle workflows for identity governance at scale.

Application Proxy

Publish on-premises web applications externally with secure remote access without VPN infrastructure.

Scroll for all 7

Semantic Vocabularies 2

JSON-LD contexts and semantic vocabularies used across these APIs.

Azure Active Directory Context

1 classes · 6 properties

JSON-LD

Microsoft Graph Identity Context

0 classes · 0 properties

JSON-LD

Spectral Rules 3

Spectral governance rulesets for linting and validating these APIs.

Microsoft Azure Active Directory API Rules

7 rules · 7 errors

SPECTRAL

Microsoft Azure Active Directory API Rules

6 rules · 4 warnings 2 info

SPECTRAL

Microsoft Azure Active Directory API Rules

11 rules · 1 errors 9 warnings 1 info

SPECTRAL

JSON Schema 55

Standalone JSON Schema definitions for this provider's data models.

Azure Active Directory User

64 properties

JSON SCHEMA

ApiApplication

5 properties

JSON SCHEMA

Application

16 properties

JSON SCHEMA

ApplicationCreate

11 properties

JSON SCHEMA

ApplicationUpdate

11 properties

JSON SCHEMA

AppRole

6 properties

JSON SCHEMA

AppRoleAssignment

8 properties

JSON SCHEMA

AssignedLicense

2 properties

JSON SCHEMA

AssignedPlan

4 properties

JSON SCHEMA

DirectoryObject

3 properties

JSON SCHEMA

Group

21 properties

JSON SCHEMA

GroupCreate

10 properties

JSON SCHEMA

GroupUpdate

8 properties

JSON SCHEMA

KeyCredential

8 properties

JSON SCHEMA

ODataError

1 properties

JSON SCHEMA

PasswordCredential

7 properties

JSON SCHEMA

PasswordProfile

3 properties

JSON SCHEMA

PermissionScope

8 properties

JSON SCHEMA

PublicClientApplication

1 properties

JSON SCHEMA

RequiredResourceAccess

2 properties

JSON SCHEMA

ServicePrincipal

21 properties

JSON SCHEMA

ServicePrincipalCreate

6 properties

JSON SCHEMA

ServicePrincipalUpdate

9 properties

JSON SCHEMA

SpaApplication

1 properties

JSON SCHEMA

User

35 properties

JSON SCHEMA

UserCreate

14 properties

JSON SCHEMA

UserUpdate

21 properties

JSON SCHEMA

WebApplication

4 properties

JSON SCHEMA

ApiApplication

5 properties

JSON SCHEMA

AppRoleAssignment

8 properties

JSON SCHEMA

AppRole

6 properties

JSON SCHEMA

ApplicationCreate

7 properties

JSON SCHEMA

Application

12 properties

JSON SCHEMA

ApplicationUpdate

7 properties

JSON SCHEMA

AssignedLicense

2 properties

JSON SCHEMA

AssignedPlan

4 properties

JSON SCHEMA

DirectoryObject

3 properties

JSON SCHEMA

GroupCreate

10 properties

JSON SCHEMA

Group

21 properties

JSON SCHEMA

GroupUpdate

8 properties

JSON SCHEMA

KeyCredential

8 properties

JSON SCHEMA

ODataError

1 properties

JSON SCHEMA

PasswordCredential

7 properties

JSON SCHEMA

PasswordProfile

3 properties

JSON SCHEMA

PermissionScope

8 properties

JSON SCHEMA

PublicClientApplication

1 properties

JSON SCHEMA

RequiredResourceAccess

2 properties

JSON SCHEMA

ServicePrincipalCreate

6 properties

JSON SCHEMA

ServicePrincipal

21 properties

JSON SCHEMA

ServicePrincipalUpdate

9 properties

JSON SCHEMA

SpaApplication

1 properties

JSON SCHEMA

UserCreate

13 properties

JSON SCHEMA

User

35 properties

JSON SCHEMA

UserUpdate

20 properties

JSON SCHEMA

WebApplication

4 properties

JSON SCHEMA

Scroll for all 55

JSON Structure 28

JSON Structure definitions describing this provider's data shapes.

Microsoft Azure Active Directory Structure

0 properties

JSON STRUCTURE

Microsoft Graph Identity Group Structure

21 properties

JSON STRUCTURE

Microsoft Graph Identity User Structure

35 properties

JSON STRUCTURE

Scroll for all 28

Examples 47

Example request and response payloads for these APIs.

Scroll for all 47

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Microsoft Azure Active Directory Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Microsoft Azure Active Directory Scopes

12 scopes · authorizationCode/clientCredentials

12 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Microsoft Azure Active Directory Agentic Access

24 operations · 13 acting

24 operations · 13 acting

AGENTIC

Use Cases 5

What developers build with this provider.

Enterprise SSO

Implement single sign-on across SaaS and on-premises applications for seamless employee access management.

B2B Collaboration

Enable secure collaboration with external partners and guests using Azure AD B2B identity federation.

Customer Identity

Build customer-facing applications with self-service sign-up, social identity providers, and branded login experiences.

Zero Trust Security

Implement zero trust architecture with conditional access policies, continuous access evaluation, and risk-based authentication.

Automated User Provisioning

Automate user account creation, updates, and deprovisioning across connected SaaS applications using SCIM.

Integrations 5

Pre-built integrations with other platforms and tools.

Microsoft 365

Native identity provider for all Microsoft 365 applications including Teams, Outlook, SharePoint, and OneDrive.

Salesforce

Single sign-on and automated user provisioning for Salesforce CRM using SAML and SCIM protocols.

ServiceNow

Federated authentication and automated user lifecycle management for ServiceNow ITSM platform.

AWS

Cross-cloud identity federation enabling Azure AD users to access AWS resources with single sign-on.

Workday

HR-driven identity provisioning with automated user creation and attribute synchronization from Workday.

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: microsoft-azure-active-directory
name: Microsoft Azure Active Directory
description: Microsoft Azure Active Directory (Azure AD), now Microsoft Entra ID, is Microsoft's cloud-based identity and
  access management service, which helps employees sign in and access resources.
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://docs.microsoft.com/azure/media/index/active-directory.svg
url: https://raw.githubusercontent.com/api-evangelist/microsoft-azure-active-directory/refs/heads/main/apis.yml
created: '2024-01-15'
modified: '2026-05-19'
specificationVersion: '0.19'
tags:
- Authentication
- Authorization
- Identity
- Microsoft
- Microsoft Entra
- OAuth
- OpenID Connect
- SAML
- SCIM
- Single Sign-On
- Zero Trust
apis:
- name: Azure AD Graph API (Deprecated)
  description: Legacy API for accessing Azure AD (deprecated in favor of Microsoft Graph).
  humanURL: https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-graph-api
  baseURL: https://graph.windows.net
  tags:
  - Deprecated
  - Identity
  - Legacy
  properties:
  - type: Documentation
    url: https://docs.microsoft.com/en-us/previous-versions/azure/ad/graph/api/api-catalog
  - type: Documentation
    url: https://docs.microsoft.com/en-us/graph/migrate-azure-ad-graph-overview
    title: Migration Guide
- name: Azure AD Authentication Library (ADAL)
  description: Authentication library for Azure AD (being replaced by MSAL).
  humanURL: https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-authentication-libraries
  tags:
  - Authentication
  - Legacy
  - Library
  properties:
  - type: Documentation
    url: https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-authentication-libraries
  - type: GitHubRepository
    url: https://github.com/AzureAD/azure-activedirectory-library-for-dotnet
- name: Microsoft Authentication Library (MSAL)
  description: Modern authentication library for Microsoft identity platform.
  humanURL: https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-overview
  tags:
  - Authentication
  - Library
  - OAuth
  - OpenID Connect
  properties:
  - type: Documentation
    url: https://docs.microsoft.com/en-us/azure/active-directory/develop/msal-overview
  - type: GitHubRepository
    url: https://github.com/AzureAD/microsoft-authentication-library-for-js
    title: JavaScript SDK
  - type: CodeExamples
    url: https://docs.microsoft.com/en-us/azure/active-directory/develop/sample-v2-code
  - type: GitHubRepository
    url: https://github.com/AzureAD/microsoft-authentication-library-for-dotnet
    title: .NET SDK
  - type: GitHubRepository
    url: https://github.com/AzureAD/microsoft-authentication-library-for-python
    title: Python SDK
  - type: GitHubRepository
    url: https://github.com/AzureAD/microsoft-authentication-library-for-java
    title: Java SDK
  - type: GitHubRepository
    url: https://github.com/AzureAD/microsoft-authentication-library-for-objc
    title: iOS SDK
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/msal/
    title: MSAL Documentation
- name: Microsoft Identity Platform
  description: The Microsoft identity platform provides authentication and authorization services using standards-compliant
    implementations of OAuth 2.0 and OpenID Connect, enabling developers to build applications that sign in users and access
    secured APIs.
  humanURL: https://learn.microsoft.com/en-us/entra/identity-platform/
  baseURL: https://login.microsoftonline.com
  tags:
  - App Registration
  - Authentication
  - Authorization
  - OAuth
  - OpenID Connect
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-protocols
    title: OAuth Documentation
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-protocols-oidc
    title: OpenID Connect Documentation
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow
    title: Authorization Code Flow
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app
    title: App Registration Guide
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/scopes-oidc
    title: Scopes and Permissions
  - type: CodeExamples
    url: https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-web-app-sign-in
- name: Microsoft Entra Verified ID API
  description: Microsoft Entra Verified ID is a managed verifiable credentials service that enables organizations to issue,
    manage, and verify decentralized identity credentials based on W3C standards.
  humanURL: https://learn.microsoft.com/en-us/entra/verified-id/
  baseURL: https://verifiedid.did.msidentity.com
  tags:
  - Decentralized Identity
  - Identity Verification
  - Verifiable Credentials
  - W3C
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/verified-id/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/entra/verified-id/admin-api
    title: Admin API
  - type: APIReference
    url: https://learn.microsoft.com/en-us/entra/verified-id/vc-network-api
    title: Network API
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/verified-id/decentralized-identifier-overview
    title: Overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/entra/verified-id/verifiable-credentials-configure-tenant
- name: Microsoft Entra ID Governance API
  description: Microsoft Entra ID Governance APIs in Microsoft Graph enable automated access reviews, entitlement management,
    lifecycle workflows, and privileged identity management for identity governance scenarios.
  humanURL: https://learn.microsoft.com/en-us/entra/id-governance/identity-governance-overview
  baseURL: https://graph.microsoft.com
  tags:
  - Access Reviews
  - Entitlement Management
  - Governance
  - Lifecycle Workflows
  - Privileged Identity Management
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/id-governance/identity-governance-overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews
    title: Access Reviews
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/id-governance/lifecycle-workflows-deployment
    title: Lifecycle Workflows
  - type: Pricing
    url: https://learn.microsoft.com/en-us/entra/id-governance/licensing-fundamentals
- name: Microsoft Entra SCIM Provisioning API
  description: Microsoft Entra ID supports SCIM 2.0 protocol for automatic user and group provisioning to cloud applications,
    enabling automated identity lifecycle management through standardized REST APIs.
  humanURL: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/use-scim-to-provision-users-and-groups
  tags:
  - Automation
  - Group Management
  - Provisioning
  - SCIM
  - User Management
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/use-scim-to-provision-users-and-groups
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/architecture/sync-scim
    title: Architecture Guide
  - type: GitHubRepository
    url: https://github.com/azure-ad-b2c/rest-api
- name: Microsoft Entra PowerShell
  description: The Microsoft Entra PowerShell module provides cmdlets for managing Microsoft Entra resources programmatically,
    built on the Microsoft Graph PowerShell SDK.
  humanURL: https://learn.microsoft.com/en-us/powershell/entra-powershell/overview?view=entra-powershell
  tags:
  - Automation
  - CLI
  - PowerShell
  - Scripting
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/powershell/entra-powershell/?view=entra-powershell
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/powershell/entra-powershell/installation?view=entra-powershell
    title: Installation
  - type: GitHubRepository
    url: https://github.com/microsoftgraph/entra-powershell
- aid: microsoft-azure-active-directory:microsoft-azure-active-directory-applications-api
  name: Microsoft Azure Active Directory Applications API
  description: Manage application registrations in Azure Active Directory. An application object is the global representation
    of an application across all tenants, defining the app identity, access configuration, and capabilities.
  humanURL: https://docs.microsoft.com/en-us/graph/overview
  baseURL: https://graph.microsoft.com
  tags:
  - Applications
  properties:
  - type: OpenAPI
    url: openapi/microsoft-azure-active-directory-applications-api-openapi.yml
  - type: Documentation
    url: https://docs.microsoft.com/en-us/graph/api/overview
  - type: Authentication
    url: https://docs.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://docs.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://azure.microsoft.com/en-us/pricing/details/active-directory/
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/use-the-api
  - type: Console
    url: https://developer.microsoft.com/en-us/graph/graph-explorer
  - type: ChangeLog
    url: https://learn.microsoft.com/en-us/graph/changelog
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-conditional-access-dev-guide
  - type: JSONSchema
    url: json-schema/azure-active-directory-user-schema.json
  - type: JSONLD
    url: json-ld/azure-active-directory-context.jsonld
- aid: microsoft-azure-active-directory:microsoft-azure-active-directory-groups-api
  name: Microsoft Azure Active Directory Groups API
  description: Manage groups in Azure Active Directory. Groups can be security groups, Microsoft 365 groups, or mail-enabled
    security groups. They provide shared access to resources for a collection of users and other directory objects.
  humanURL: https://docs.microsoft.com/en-us/graph/overview
  baseURL: https://graph.microsoft.com
  tags:
  - Groups
  properties:
  - type: OpenAPI
    url: openapi/microsoft-azure-active-directory-groups-api-openapi.yml
  - type: Documentation
    url: https://docs.microsoft.com/en-us/graph/api/overview
  - type: Authentication
    url: https://docs.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://docs.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://azure.microsoft.com/en-us/pricing/details/active-directory/
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/use-the-api
  - type: Console
    url: https://developer.microsoft.com/en-us/graph/graph-explorer
  - type: ChangeLog
    url: https://learn.microsoft.com/en-us/graph/changelog
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-conditional-access-dev-guide
  - type: JSONSchema
    url: json-schema/azure-active-directory-user-schema.json
  - type: JSONLD
    url: json-ld/azure-active-directory-context.jsonld
- aid: microsoft-azure-active-directory:microsoft-azure-active-directory-service-principals-api
  name: Microsoft Azure Active Directory Service Principals API
  description: Manage service principals in Azure Active Directory. A service principal is the local representation of an
    application in a specific tenant. It defines what the application can do in the tenant, who can access it, and what resources
    it can access.
  humanURL: https://docs.microsoft.com/en-us/graph/overview
  baseURL: https://graph.microsoft.com
  tags:
  - Service Principals
  properties:
  - type: OpenAPI
    url: openapi/microsoft-azure-active-directory-service-principals-api-openapi.yml
  - type: Documentation
    url: https://docs.microsoft.com/en-us/graph/api/overview
  - type: Authentication
    url: https://docs.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://docs.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://azure.microsoft.com/en-us/pricing/details/active-directory/
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/use-the-api
  - type: Console
    url: https://developer.microsoft.com/en-us/graph/graph-explorer
  - type: ChangeLog
    url: https://learn.microsoft.com/en-us/graph/changelog
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-conditional-access-dev-guide
  - type: JSONSchema
    url: json-schema/azure-active-directory-user-schema.json
  - type: JSONLD
    url: json-ld/azure-active-directory-context.jsonld
- aid: microsoft-azure-active-directory:microsoft-azure-active-directory-users-api
  name: Microsoft Azure Active Directory Users API
  description: Manage user accounts in Azure Active Directory. Users are the core identity objects representing people in
    an organization. Each user has a profile with attributes such as display name, email, job title, and authentication credentials.
  humanURL: https://docs.microsoft.com/en-us/graph/overview
  baseURL: https://graph.microsoft.com
  tags:
  - Users
  properties:
  - type: OpenAPI
    url: openapi/microsoft-azure-active-directory-users-api-openapi.yml
  - type: Documentation
    url: https://docs.microsoft.com/en-us/graph/api/overview
  - type: Authentication
    url: https://docs.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://docs.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://azure.microsoft.com/en-us/pricing/details/active-directory/
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/use-the-api
  - type: Console
    url: https://developer.microsoft.com/en-us/graph/graph-explorer
  - type: ChangeLog
    url: https://learn.microsoft.com/en-us/graph/changelog
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview?view=graph-rest-1.0
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-conditional-access-dev-guide
  - type: JSONSchema
    url: json-schema/azure-active-directory-user-schema.json
  - type: JSONLD
    url: json-ld/azure-active-directory-context.jsonld
maintainers:
- name: Microsoft
  email: azuread@microsoft.com
  url: https://azure.microsoft.com/en-us/services/active-directory/
- name: Kin Lane
  email: kin@apievangelist.com
  url: https://apievangelist.com
common:
- type: AgenticAccess
  url: agentic-access/microsoft-azure-active-directory-agentic-access.yml
- type: DomainSecurity
  url: security/microsoft-azure-active-directory-domain-security.yml
- type: Authentication
  url: authentication/microsoft-azure-active-directory-authentication.yml
- type: OAuthScopes
  url: scopes/microsoft-azure-active-directory-scopes.yml
- type: Portal
  url: https://portal.azure.com/
- type: StatusPage
  url: https://status.azure.com/
- type: Support
  url: https://azure.microsoft.com/en-us/support/
- type: Blog
  url: https://techcommunity.microsoft.com/t5/azure-active-directory/bg-p/Azure-Active-Directory
- type: TermsOfService
  url: https://azure.microsoft.com/en-us/support/legal/
- type: PrivacyPolicy
  url: https://privacy.microsoft.com/en-us/privacystatement
- type: Pricing
  url: https://azure.microsoft.com/en-us/pricing/details/active-directory/
- type: Training
  url: https://docs.microsoft.com/en-us/learn/azure/
- type: Portal
  url: https://entra.microsoft.com
  title: Entra Admin Center
- type: DeveloperPortal
  url: https://developer.microsoft.com/en-us/graph
- type: Blog
  url: https://devblogs.microsoft.com/identity/
  title: Identity Developer Blog
- url: https://devblogs.microsoft.com/identity/feed/
  type: BlogRSS
  description: Discovered RSS/Atom feed for https://devblogs.microsoft.com/identity/
- type: ReleaseNotes
  url: https://learn.microsoft.com/en-us/entra/fundamentals/whats-new
- type: Documentation
  url: https://learn.microsoft.com/en-us/entra/identity/
  title: Entra Documentation
- type: Console
  url: https://developer.microsoft.com/en-us/graph/graph-explorer
  title: Graph Explorer
- type: GitHubOrganization
  url: https://github.com/AzureAD
- type: OpenAPI
  url: openapi/microsoft-graph-identity-api.yml
- type: JSONSchema
  url: json-schema/azure-active-directory-user-schema.json
- type: JSONLD
  url: json-ld/azure-active-directory-context.jsonld
- type: Features
  data:
  - name: Single Sign-On
    description: Enable users to sign in once and access all connected applications without re-authenticating.
  - name: Conditional Access
    description: Enforce granular access policies based on user, device, location, and risk signals for zero trust security.
  - name: Multi-Factor Authentication
    description: Add a second layer of security with phone, app, or hardware token verification for identity protection.
  - name: SCIM User Provisioning
    description: Automate user and group lifecycle management across cloud applications using SCIM 2.0 standard.
  - name: Verifiable Credentials
    description: Issue and verify decentralized identity credentials based on W3C standards for privacy-preserving identity
      verification.
  - name: Identity Governance
    description: Automate access reviews, entitlement management, and lifecycle workflows for identity governance at scale.
  - name: Application Proxy
    description: Publish on-premises web applications externally with secure remote access without VPN infrastructure.
- type: UseCases
  data:
  - name: Enterprise SSO
    description: Implement single sign-on across SaaS and on-premises applications for seamless employee access management.
  - name: B2B Collaboration
    description: Enable secure collaboration with external partners and guests using Azure AD B2B identity federation.
  - name: Customer Identity
    description: Build customer-facing applications with self-service sign-up, social identity providers, and branded login
      experiences.
  - name: Zero Trust Security
    description: Implement zero trust architecture with conditional access policies, continuous access evaluation, and risk-based
      authentication.
  - name: Automated User Provisioning
    description: Automate user account creation, updates, and deprovisioning across connected SaaS applications using SCIM.
- type: Integrations
  data:
  - name: Microsoft 365
    description: Native identity provider for all Microsoft 365 applications including Teams, Outlook, SharePoint, and OneDrive.
  - name: Salesforce
    description: Single sign-on and automated user provisioning for Salesforce CRM using SAML and SCIM protocols.
  - name: ServiceNow
    description: Federated authentication and automated user lifecycle management for ServiceNow ITSM platform.
  - name: AWS
    description: Cross-cloud identity federation enabling Azure AD users to access AWS resources with single sign-on.
  - name: Workday
    description: HR-driven identity provisioning with automated user creation and attribute synchronization from Workday.
include:
- name: Microsoft Identity Platform
  url: https://docs.microsoft.com/en-us/azure/active-directory/develop/
- name: Azure AD B2C
  url: https://azure.microsoft.com/en-us/services/active-directory/external-identities/b2c/
- name: Azure AD B2B
  url: https://docs.microsoft.com/en-us/azure/active-directory/external-identities/
- name: Microsoft Entra External ID
  url: https://learn.microsoft.com/en-us/entra/external-id/self-service-sign-up-secure-api-connector
- name: Microsoft Entra ID Protection
  url: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-graph-api