Microsoft Entra
Microsoft Entra (formerly Azure Active Directory) provides identity and access management services including authentication, authorization, and directory services.
Microsoft Entra publishes 17 APIs on the APIs.io network, including Applications API, Groups API, Users API, and 14 more. Tagged areas include Access Management, Authentication, Azure AD, Entra, and Identity.
The Microsoft Entra catalog on APIs.io includes 2 JSON-LD contexts and 2 Spectral governance rulesets.
Microsoft Entra’s developer surface includes authentication, developer portal, getting-started guide, engineering blog, support, changelog, pricing, and 33 more developer resources.
What this lets a business do 1
Business capabilities this provider's published APIs can perform, derived from its own contracts. Browse all capabilities →
Kin Score
What adopting Microsoft Entra External ID moves on the Kin Score 4
Microsoft Entra External ID is an area vendor: providers adopt it to run part of their developer surface. This is the Kin Score checks its features can move for a provider that adopts it, what each one really earns, and what it earns nothing for.
Entra External ID lifts almost nothing on the identity dimensions as the rubric reads them today. Its discovery documents live under a tenant path, not at a host root, so a provider using a custom URL domain still is not read as serving discovery; it can earn the OpenAPI fallback tiers only by declaring OAuth in its own contract. There is no dynamic client registration (Microsoft says so for MCP), and no protected-resource metadata. Hosted user flows give a sign-up page the provider can declare.
| Check | Earns | Through |
|---|---|---|
| Machine-Readable Authpartial Agent ReadinessThe served tier reads a root /.well-known/openid-configuration on a provider host; Entra’s is under / |
7.5 of 10 | Tenant-scoped OIDC discovery |
| Delegated User Identitypartial Agent ReadinessSame tenant-path reason; the documented tier reads an authorizationCode flow or openIdConnect in the provider’s OpenAPI. |
3.0 of 6 | Tenant-scoped OIDC discovery |
| Self-service sign-up Access ClarityDeclare the user-flow sign-up URL as a Login or SignUp pointer in apis.yml. |
5.0 of 5 | Sign-up and sign-in user flows |
| FAPI / hardened authorization profileconditional RegulatoryBanking/open-finance regime only, and only if the provider’s own auth documentation states it uses private_key_jwt or certificate-bound client authentication. |
6.0 of 6 | Tenant-scoped OIDC discovery |
What Microsoft Entra External ID ships that earns nothing (2)
- Custom URL domains — A custom URL domain puts discovery on the provider’s host but still under /
/v2.0/, so it reads exactly as the ciamlogin.com default does. - Tenant-scoped OIDC discovery — openid-configuration is not one of the well-known documents that check reads.
A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. The rating is not for sale → · Full vendor facets artifact
Standards implemented 1
Interfaces this provider implements that became standards by being copied rather than ratified. Each is profiled by the API Commons, and the evidence column says how the claim was established — not that it was made.
APIs 17
Individual APIs this provider publishes, each with its own machine-readable definition.
Microsoft Entra ID Protection API
API for identity risk detection, investigation, and remediation.
Microsoft Entra Conditional Access API
API for managing conditional access policies and controls.
Microsoft Entra Privileged Identity Management API
API for managing privileged access and just-in-time administration.
Microsoft Entra Verified ID API
API for issuing and verifying decentralized identity credentials.
Microsoft Entra External ID API
API for managing customer and partner identity and access management.
Microsoft Entra ID Governance API
API for managing identity governance including access reviews, entitlement management, and lifecycle workflows to ensure the right people have the right access at the right time.
Microsoft Entra Application Management API
API for registering, configuring, and managing applications and service principals in Microsoft Entra ID.
Microsoft Entra Authentication Methods API
API for managing user authentication methods including FIDO2 security keys, passwordless phone sign-in, Microsoft Authenticator, and MFA registration.
Microsoft Entra Workload ID API
API for managing and securing identities for software workloads such as applications, services, scripts, and containers.
Microsoft Entra Provisioning API
API for automating user provisioning and deprovisioning using SCIM protocol, including API-driven inbound provisioning from any system of record.
Microsoft Entra Global Secure Access API
API for managing Microsoft Entra Internet Access and Microsoft Entra Private Access, providing identity-centric secure web gateway and zero-trust network access.
Microsoft Identity Platform API
API endpoints for OAuth 2.0, OpenID Connect, and SAML authentication protocols enabling application integration with Microsoft Entra ID.
Microsoft Entra Agent ID API
API for creating, securing, and monitoring AI agent identities, providing authentication, authorization, and lifecycle management for AI agents.
Microsoft Entra Applications API
Register and manage application objects that define application configuration including credentials, permissions, and sign-in settings
Microsoft Entra Groups API
Manage groups for organizing users, devices, and other principals including Microsoft 365 groups, security groups, and distribution lists
Microsoft Entra Users API
Manage user accounts in the directory including creation, updates, profile management, and lifecycle operations
Microsoft Entra Service Principals API
Manage service principal objects that represent application instances in a tenant for authentication and authorization
Scroll for all 17
Postman Collections 1
Ready-to-run Postman collections for exercising this provider's APIs.
Open Collections 6
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONMicrosoft Entra Microsoft Graph Identity Applications API
OPEN COLLECTIONMicrosoft Entra Microsoft Graph Identity API
OPEN COLLECTIONArazzo Workflows 14
Multi-step API workflows described with the Arazzo specification.
Microsoft Entra Audit User Memberships
Find a user by UPN, read its profile, and list its group memberships.
ARAZZOMicrosoft Entra Create Group With Member
Create a security group, add a member, and list its members.
ARAZZOMicrosoft Entra Create Microsoft 365 Group With Member
Create a Unified M365 group, add a member, and read the group back.
ARAZZOMicrosoft Entra Decommission Application
Find a service principal by appId, delete it, then delete the app.
ARAZZOMicrosoft Entra Deprovision User
Disable a user account, then delete the user from the directory.
ARAZZOMicrosoft Entra Find And Update Application
Find an app by appId, update its display name, and read it back.
ARAZZOMicrosoft Entra Find And Update Group
Find a group by display name, update it, and read it back.
ARAZZOMicrosoft Entra Find And Update User
Find a user by UPN, update its profile, and read the result.
ARAZZOMicrosoft Entra Grant App Role Assignment
Grant an app role to a service principal then list its assignments.
ARAZZOMicrosoft Entra Offboard User From Group
Find a user by UPN, remove it from a group, and verify removal.
ARAZZOMicrosoft Entra Onboard User To Group
Create a user, add it to an existing group, and confirm membership.
ARAZZOMicrosoft Entra Provision User
Create a new Entra ID user and read back the provisioned account.
ARAZZOMicrosoft Entra Register Application With Service Principal
Create an app registration then instantiate its service principal.
ARAZZOMicrosoft Entra Rotate Application Secret
Add a fresh client secret to an app, then remove the old one.
ARAZZOScroll for all 14
Pricing Plans 2
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Microsoft Entra Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Microsoft Entra Finops
FINOPSFeatures 8
Notable capabilities this provider offers.
Identity and Access Management
Manage user identities, authentication, and authorization across cloud and hybrid environments with single sign-on.
Conditional Access
Enforce adaptive access policies based on user, device, location, and risk signals for zero trust security.
Identity Governance
Automate access reviews, entitlement management, and lifecycle workflows to ensure proper access controls.
Privileged Identity Management
Manage, control, and monitor privileged access with just-in-time and approval-based activation.
Verified ID
Issue and verify decentralized identity credentials using open standards for portable, self-sovereign identity.
External Identities
Enable secure collaboration with external partners and customers through B2B and B2C identity management.
Global Secure Access
Provide identity-centric secure web gateway and zero-trust network access for internet and private resources.
Workload Identities
Secure and manage identities for applications, services, scripts, and containers running as software workloads.
Scroll for all 8
Semantic Vocabularies 2
JSON-LD contexts and semantic vocabularies used across these APIs.
Spectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Microsoft Entra API Rules
SPECTRALMicrosoft Entra API Rules
SPECTRALJSON Schema 48
Standalone JSON Schema definitions for this provider's data models.
ApiApplication
JSON SCHEMAMicrosoft Entra Application
JSON SCHEMAApplicationCollectionResponse
JSON SCHEMAAppRole
JSON SCHEMAAppRoleAssignment
JSON SCHEMAAppRoleAssignmentCollectionResponse
JSON SCHEMAAssignedLicense
JSON SCHEMADirectoryObject
JSON SCHEMADirectoryObjectCollectionResponse
JSON SCHEMAApiApplication
JSON SCHEMAAppRoleAssignmentCollectionResponse
JSON SCHEMAAppRoleAssignment
JSON SCHEMAAppRole
JSON SCHEMAApplicationCollectionResponse
JSON SCHEMAApplication
JSON SCHEMAAssignedLicense
JSON SCHEMADirectoryObjectCollectionResponse
JSON SCHEMADirectoryObject
JSON SCHEMAGroupCollectionResponse
JSON SCHEMAGroup
JSON SCHEMAKeyCredential
JSON SCHEMAODataError
JSON SCHEMAODataReference
JSON SCHEMAPasswordCredential
JSON SCHEMAPasswordProfile
JSON SCHEMAPermissionScope
JSON SCHEMARequiredResourceAccess
JSON SCHEMAServicePrincipalCollectionResponse
JSON SCHEMAServicePrincipal
JSON SCHEMASpaApplication
JSON SCHEMAUserCollectionResponse
JSON SCHEMAUser
JSON SCHEMAWebApplication
JSON SCHEMAGroup
JSON SCHEMAGroupCollectionResponse
JSON SCHEMAKeyCredential
JSON SCHEMAODataError
JSON SCHEMAODataReference
JSON SCHEMAPasswordCredential
JSON SCHEMAPasswordProfile
JSON SCHEMAPermissionScope
JSON SCHEMARequiredResourceAccess
JSON SCHEMAServicePrincipal
JSON SCHEMAServicePrincipalCollectionResponse
JSON SCHEMASpaApplication
JSON SCHEMAMicrosoft Entra User
JSON SCHEMAUserCollectionResponse
JSON SCHEMAWebApplication
JSON SCHEMAScroll for all 48
JSON Structure 25
JSON Structure definitions describing this provider's data shapes.
Microsoft Entra Graph Identity Api Application Structure
JSON STRUCTUREMicrosoft Entra Graph Identity App Role Structure
JSON STRUCTUREMicrosoft Entra Graph Identity Application Structure
JSON STRUCTUREMicrosoft Entra Graph Identity Group Structure
JSON STRUCTUREMicrosoft Entra Graph Identity Key Credential Structure
JSON STRUCTUREMicrosoft Entra Graph Identity O Data Error Structure
JSON STRUCTUREMicrosoft Entra Graph Identity Spa Application Structure
JSON STRUCTUREMicrosoft Entra Graph Identity User Structure
JSON STRUCTUREMicrosoft Entra Graph Identity Web Application Structure
JSON STRUCTUREMicrosoft Entra Structure
JSON STRUCTUREScroll for all 25
Examples 24
Example request and response payloads for these APIs.
Scroll for all 24
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 5
What developers build with this provider.
Zero Trust Implementation
Implement zero trust architecture with identity-based access controls, conditional access policies, and continuous verification.
Hybrid Identity Management
Synchronize and manage identities across on-premises Active Directory and cloud environments.
Application Single Sign-On
Enable SSO for thousands of SaaS and on-premises applications with SAML, OIDC, and password-based authentication.
Automated User Provisioning
Automate user lifecycle management with SCIM-based provisioning and deprovisioning across integrated applications.
AI Agent Identity Management
Create, secure, and monitor identities for AI agents with authentication, authorization, and lifecycle management.
Integrations 8
Pre-built integrations with other platforms and tools.
Microsoft 365
Deep integration for identity and access management across all Microsoft 365 applications and services.
Azure Services
Native identity provider for Azure resources including VMs, databases, storage, and managed identities.
Active Directory
Hybrid identity synchronization with on-premises Active Directory using Azure AD Connect.
Salesforce
SAML and SCIM integration for single sign-on and automated user provisioning with Salesforce.
ServiceNow
SSO and automated provisioning integration with ServiceNow ITSM platform.
Workday
Inbound provisioning from Workday HR to automate user lifecycle management.
SAP
SSO and provisioning integration with SAP applications and S/4HANA.
Okta
Cross-platform identity federation and migration support with Okta identity provider.
Scroll for all 8
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 15
Pagination, idempotency, versioning, errors, and events
Scroll for all 15
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 5
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 4
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 2
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.