Microsoft Entra website screenshot

Microsoft Entra

Microsoft Entra (formerly Azure Active Directory) provides identity and access management services including authentication, authorization, and directory services.

Microsoft Entra publishes 4 APIs on the APIs.io network, including Applications API, Groups API, ServicePrincipals API, and 1 more. Tagged areas include Access Management, Authentication, Azure AD, Entra, and Identity.

The Microsoft Entra catalog on APIs.io includes 2 JSON-LD contexts and 2 Spectral governance rulesets.

Microsoft Entra’s developer surface includes authentication, developer portal, getting-started guide, engineering blog, support, changelog, pricing, and 28 more developer resources.

62.7/100 strong ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
17 APIs 8 Features 5 Use Cases
Access ManagementAuthenticationAzure ADEntraIdentityIdentity GovernanceMicrosoftNetwork SecuritySecurityZero Trust

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 62.7/100 · strong
Contract Quality 16.5 / 25
Developer Ergonomics 9.6 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 8.9 / 13
Governance 7.0 / 12
Discoverability 6.5 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/microsoft-entra: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 17

Individual APIs this provider publishes, each with its own machine-readable definition.

Microsoft Entra ID Protection API

API for identity risk detection, investigation, and remediation.

Microsoft Entra Conditional Access API

API for managing conditional access policies and controls.

Microsoft Entra Privileged Identity Management API

API for managing privileged access and just-in-time administration.

Microsoft Entra Verified ID API

API for issuing and verifying decentralized identity credentials.

Microsoft Entra External ID API

API for managing customer and partner identity and access management.

Microsoft Entra ID Governance API

API for managing identity governance including access reviews, entitlement management, and lifecycle workflows to ensure the right people have the right access at the right time.

Microsoft Entra Application Management API

API for registering, configuring, and managing applications and service principals in Microsoft Entra ID.

Microsoft Entra Authentication Methods API

API for managing user authentication methods including FIDO2 security keys, passwordless phone sign-in, Microsoft Authenticator, and MFA registration.

Microsoft Entra Workload ID API

API for managing and securing identities for software workloads such as applications, services, scripts, and containers.

Microsoft Entra Provisioning API

API for automating user provisioning and deprovisioning using SCIM protocol, including API-driven inbound provisioning from any system of record.

Microsoft Entra Global Secure Access API

API for managing Microsoft Entra Internet Access and Microsoft Entra Private Access, providing identity-centric secure web gateway and zero-trust network access.

Microsoft Identity Platform API

API endpoints for OAuth 2.0, OpenID Connect, and SAML authentication protocols enabling application integration with Microsoft Entra ID.

Microsoft Entra Agent ID API

API for creating, securing, and monitoring AI agent identities, providing authentication, authorization, and lifecycle management for AI agents.

Microsoft Entra Applications API

Register and manage application objects that define application configuration including credentials, permissions, and sign-in settings

Microsoft Entra Groups API

Manage groups for organizing users, devices, and other principals including Microsoft 365 groups, security groups, and distribution lists

Microsoft Entra ServicePrincipals API

Manage service principal objects that represent application instances in a tenant for authentication and authorization

Microsoft Entra Users API

Manage user accounts in the directory including creation, updates, profile management, and lifecycle operations

Scroll for all 17

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Arazzo Workflows 14

Multi-step API workflows described with the Arazzo specification.

Microsoft Entra Audit User Memberships

Find a user by UPN, read its profile, and list its group memberships.

ARAZZO

Microsoft Entra Create Group With Member

Create a security group, add a member, and list its members.

ARAZZO

Microsoft Entra Create Microsoft 365 Group With Member

Create a Unified M365 group, add a member, and read the group back.

ARAZZO

Microsoft Entra Decommission Application

Find a service principal by appId, delete it, then delete the app.

ARAZZO

Microsoft Entra Deprovision User

Disable a user account, then delete the user from the directory.

ARAZZO

Microsoft Entra Find And Update Application

Find an app by appId, update its display name, and read it back.

ARAZZO

Microsoft Entra Find And Update Group

Find a group by display name, update it, and read it back.

ARAZZO

Microsoft Entra Find And Update User

Find a user by UPN, update its profile, and read the result.

ARAZZO

Microsoft Entra Grant App Role Assignment

Grant an app role to a service principal then list its assignments.

ARAZZO

Microsoft Entra Offboard User From Group

Find a user by UPN, remove it from a group, and verify removal.

ARAZZO

Microsoft Entra Onboard User To Group

Create a user, add it to an existing group, and confirm membership.

ARAZZO

Microsoft Entra Provision User

Create a new Entra ID user and read back the provisioned account.

ARAZZO

Microsoft Entra Register Application With Service Principal

Create an app registration then instantiate its service principal.

ARAZZO

Microsoft Entra Rotate Application Secret

Add a fresh client secret to an app, then remove the old one.

ARAZZO

Scroll for all 14

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Microsoft Entra Rate Limits

9 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Identity and Access Management

Manage user identities, authentication, and authorization across cloud and hybrid environments with single sign-on.

Conditional Access

Enforce adaptive access policies based on user, device, location, and risk signals for zero trust security.

Identity Governance

Automate access reviews, entitlement management, and lifecycle workflows to ensure proper access controls.

Privileged Identity Management

Manage, control, and monitor privileged access with just-in-time and approval-based activation.

Verified ID

Issue and verify decentralized identity credentials using open standards for portable, self-sovereign identity.

External Identities

Enable secure collaboration with external partners and customers through B2B and B2C identity management.

Global Secure Access

Provide identity-centric secure web gateway and zero-trust network access for internet and private resources.

Workload Identities

Secure and manage identities for applications, services, scripts, and containers running as software workloads.

Scroll for all 8

Semantic Vocabularies 2

JSON-LD contexts and semantic vocabularies used across these APIs.

Microsoft Entra Context

0 classes · 5 properties

JSON-LD

Microsoft Entra Graph Identity Context

0 classes · 0 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Microsoft Entra API Rules

6 rules · 4 warnings 2 info

SPECTRAL

Microsoft Entra API Rules

17 rules · 8 errors 8 warnings 1 info

SPECTRAL

JSON Schema 48

Standalone JSON Schema definitions for this provider's data models.

ApiApplication

5 properties

JSON SCHEMA

Microsoft Entra Application

24 properties

JSON SCHEMA

ApplicationCollectionResponse

4 properties

JSON SCHEMA

AppRole

6 properties

JSON SCHEMA

AppRoleAssignment

8 properties

JSON SCHEMA

AppRoleAssignmentCollectionResponse

4 properties

JSON SCHEMA

AssignedLicense

2 properties

JSON SCHEMA

DirectoryObject

3 properties

JSON SCHEMA

DirectoryObjectCollectionResponse

4 properties

JSON SCHEMA

ApiApplication

5 properties

JSON SCHEMA

AppRoleAssignmentCollectionResponse

4 properties

JSON SCHEMA

AppRoleAssignment

8 properties

JSON SCHEMA

AppRole

6 properties

JSON SCHEMA

ApplicationCollectionResponse

4 properties

JSON SCHEMA

Application

13 properties

JSON SCHEMA

AssignedLicense

2 properties

JSON SCHEMA

DirectoryObjectCollectionResponse

4 properties

JSON SCHEMA

DirectoryObject

3 properties

JSON SCHEMA

GroupCollectionResponse

4 properties

JSON SCHEMA

Group

18 properties

JSON SCHEMA

KeyCredential

7 properties

JSON SCHEMA

ODataError

1 properties

JSON SCHEMA

ODataReference

1 properties

JSON SCHEMA

PasswordCredential

6 properties

JSON SCHEMA

PasswordProfile

3 properties

JSON SCHEMA

PermissionScope

8 properties

JSON SCHEMA

RequiredResourceAccess

2 properties

JSON SCHEMA

ServicePrincipalCollectionResponse

4 properties

JSON SCHEMA

ServicePrincipal

20 properties

JSON SCHEMA

SpaApplication

1 properties

JSON SCHEMA

UserCollectionResponse

4 properties

JSON SCHEMA

User

31 properties

JSON SCHEMA

WebApplication

4 properties

JSON SCHEMA

Group

18 properties

JSON SCHEMA

GroupCollectionResponse

4 properties

JSON SCHEMA

KeyCredential

7 properties

JSON SCHEMA

ODataError

1 properties

JSON SCHEMA

ODataReference

1 properties

JSON SCHEMA

PasswordCredential

6 properties

JSON SCHEMA

PasswordProfile

3 properties

JSON SCHEMA

PermissionScope

8 properties

JSON SCHEMA

RequiredResourceAccess

2 properties

JSON SCHEMA

ServicePrincipal

20 properties

JSON SCHEMA

ServicePrincipalCollectionResponse

4 properties

JSON SCHEMA

SpaApplication

1 properties

JSON SCHEMA

Microsoft Entra User

39 properties

JSON SCHEMA

UserCollectionResponse

4 properties

JSON SCHEMA

WebApplication

4 properties

JSON SCHEMA

Scroll for all 48

JSON Structure 25

JSON Structure definitions describing this provider's data shapes.

Microsoft Entra Structure

0 properties

JSON STRUCTURE

Scroll for all 25

Examples 24

Example request and response payloads for these APIs.

Scroll for all 24

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Microsoft Entra Authentication

oauth2 · 1 scheme

SECURITY

Microsoft Entra Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Microsoft Entra Vulnerability Disclosure

security.txt · contact published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Microsoft Entra Scopes

13 scopes · authorizationCode/clientCredentials

13 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Microsoft Entra Agentic Access

28 operations · 17 acting

28 operations · 17 acting

AGENTIC

Use Cases 5

What developers build with this provider.

Zero Trust Implementation

Implement zero trust architecture with identity-based access controls, conditional access policies, and continuous verification.

Hybrid Identity Management

Synchronize and manage identities across on-premises Active Directory and cloud environments.

Application Single Sign-On

Enable SSO for thousands of SaaS and on-premises applications with SAML, OIDC, and password-based authentication.

Automated User Provisioning

Automate user lifecycle management with SCIM-based provisioning and deprovisioning across integrated applications.

AI Agent Identity Management

Create, secure, and monitor identities for AI agents with authentication, authorization, and lifecycle management.

Integrations 8

Pre-built integrations with other platforms and tools.

Microsoft 365

Deep integration for identity and access management across all Microsoft 365 applications and services.

Azure Services

Native identity provider for Azure resources including VMs, databases, storage, and managed identities.

Active Directory

Hybrid identity synchronization with on-premises Active Directory using Azure AD Connect.

Salesforce

SAML and SCIM integration for single sign-on and automated user provisioning with Salesforce.

ServiceNow

SSO and automated provisioning integration with ServiceNow ITSM platform.

Workday

Inbound provisioning from Workday HR to automate user lifecycle management.

SAP

SSO and provisioning integration with SAP applications and S/4HANA.

Okta

Cross-platform identity federation and migration support with Okta identity provider.

Scroll for all 8

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 15

Pagination, idempotency, versioning, errors, and events

Scroll for all 15

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: microsoft-entra
name: Microsoft Entra
description: Microsoft Entra (formerly Azure Active Directory) provides identity and access management services including
  authentication, authorization, and directory services.
url: https://raw.githubusercontent.com/api-evangelist/microsoft-entra/refs/heads/main/apis.yml
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://www.microsoft.com/en-us/security/content/dam/microsoft/final/security/includes/microsoft-entra-logo.svg
created: '2024-01-01'
modified: '2026-05-19'
specificationVersion: '0.19'
type: Index
access: 3rd-Party
tags:
- Access Management
- Authentication
- Azure AD
- Entra
- Identity
- Identity Governance
- Microsoft
- Network Security
- Security
- Zero Trust
apis:
- aid: microsoft-entra:id-protection
  name: Microsoft Entra ID Protection API
  description: API for identity risk detection, investigation, and remediation.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/identityprotection-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Identity Protection
  - Risk Detection
  - Security
  - Threat Protection
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/id-protection/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identityprotectionroot
- aid: microsoft-entra:conditional-access
  name: Microsoft Entra Conditional Access API
  description: API for managing conditional access policies and controls.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccessroot
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Access Control
  - Conditional Access
  - Policies
  - Security
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/conditional-access/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccessroot
- aid: microsoft-entra:pim
  name: Microsoft Entra Privileged Identity Management API
  description: API for managing privileged access and just-in-time administration.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/privilegedidentitymanagementv3-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Just-In-Time
  - PIM
  - Privileged Access
  - Role Management
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/privilegedidentitymanagementv3-overview
- aid: microsoft-entra:verified-id
  name: Microsoft Entra Verified ID API
  description: API for issuing and verifying decentralized identity credentials.
  humanURL: https://learn.microsoft.com/en-us/entra/verified-id/
  baseURL: https://verifiedid.did.msidentity.com/v1.0
  tags:
  - Decentralized Identity
  - DID
  - SSI
  - Verifiable Credentials
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/verified-id/verifiable-credentials-configure-tenant
  - type: APIReference
    url: https://learn.microsoft.com/en-us/entra/verified-id/get-started-request-api
- aid: microsoft-entra:external-id
  name: Microsoft Entra External ID API
  description: API for managing customer and partner identity and access management.
  humanURL: https://learn.microsoft.com/en-us/entra/external-id/
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - B2B
  - B2C
  - Customer Identity
  - External Identities
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/external-id/external-identities-overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview
- aid: microsoft-entra:id-governance
  name: Microsoft Entra ID Governance API
  description: API for managing identity governance including access reviews, entitlement management, and lifecycle workflows
    to ensure the right people have the right access at the right time.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Access Reviews
  - Compliance
  - Entitlement Management
  - Identity Governance
  - Lifecycle Workflows
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/id-governance/identity-governance-overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-access-package-api
- aid: microsoft-entra:application-management
  name: Microsoft Entra Application Management API
  description: API for registering, configuring, and managing applications and service principals in Microsoft Entra ID.
  humanURL: https://learn.microsoft.com/en-us/graph/applications-concept-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - App Registration
  - Applications
  - Credentials
  - OAuth
  - Service Principals
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/applications-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-applications-basics
- aid: microsoft-entra:authentication-methods
  name: Microsoft Entra Authentication Methods API
  description: API for managing user authentication methods including FIDO2 security keys, passwordless phone sign-in, Microsoft
    Authenticator, and MFA registration.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethods-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Authentication Methods
  - FIDO2
  - MFA
  - Passkeys
  - Passwordless
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-methods
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/authenticationmethods-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/authenticationmethods-get-started
- aid: microsoft-entra:workload-id
  name: Microsoft Entra Workload ID API
  description: API for managing and securing identities for software workloads such as applications, services, scripts, and
    containers.
  humanURL: https://learn.microsoft.com/en-us/entra/workload-id/
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Managed Identities
  - Service Principals
  - Workload Identities
  - Workload Identity Federation
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/workload-id/workload-identities-overview
- aid: microsoft-entra:provisioning
  name: Microsoft Entra Provisioning API
  description: API for automating user provisioning and deprovisioning using SCIM protocol, including API-driven inbound provisioning
    from any system of record.
  humanURL: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/inbound-provisioning-api-concepts
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Inbound Provisioning
  - Provisioning
  - SCIM
  - Synchronization
  - User Lifecycle
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/how-provisioning-works
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/synchronization-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/inbound-provisioning-api-configure-app
- aid: microsoft-entra:global-secure-access
  name: Microsoft Entra Global Secure Access API
  description: API for managing Microsoft Entra Internet Access and Microsoft Entra Private Access, providing identity-centric
    secure web gateway and zero-trust network access.
  humanURL: https://learn.microsoft.com/en-us/entra/global-secure-access/overview-what-is-global-secure-access
  baseURL: https://graph.microsoft.com/beta
  tags:
  - Internet Access
  - Network Security
  - Private Access
  - Secure Web Gateway
  - Zero Trust
  - ZTNA
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/global-secure-access/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/networkaccess-global-secure-access-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-entra-private-access
- aid: microsoft-entra:identity-platform
  name: Microsoft Identity Platform API
  description: API endpoints for OAuth 2.0, OpenID Connect, and SAML authentication protocols enabling application integration
    with Microsoft Entra ID.
  humanURL: https://learn.microsoft.com/en-us/entra/identity-platform/
  baseURL: https://login.microsoftonline.com
  tags:
  - Identity Platform
  - OAuth 2.0
  - OpenID Connect
  - SAML
  - Token Service
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity-platform/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/entra/identity-platform/v2-protocols
- aid: microsoft-entra:agent-id
  name: Microsoft Entra Agent ID API
  description: API for creating, securing, and monitoring AI agent identities, providing authentication, authorization, and
    lifecycle management for AI agents.
  humanURL: https://learn.microsoft.com/en-us/graph/api/resources/agentid-platform-overview
  baseURL: https://graph.microsoft.com/beta
  tags:
  - Agent Identity
  - Agent Registry
  - AI Agents
  - Machine Identity
  properties:
  - type: Documentation
    url: https://learn.microsoft.com/en-us/graph/api/resources/agentid-platform-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/entra/agent-id/identity-platform/interactive-agent-request-user-tokens
- aid: microsoft-entra:microsoft-entra-applications-api
  name: Microsoft Entra Applications API
  description: Register and manage application objects that define application configuration including credentials, permissions,
    and sign-in settings
  humanURL: https://learn.microsoft.com/en-us/graph/azuread-identity-access-management-concept-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Applications
  properties:
  - type: OpenAPI
    url: openapi/microsoft-entra-applications-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/
  - type: Authentication
    url: https://learn.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-applications-basics
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview
- aid: microsoft-entra:microsoft-entra-groups-api
  name: Microsoft Entra Groups API
  description: Manage groups for organizing users, devices, and other principals including Microsoft 365 groups, security
    groups, and distribution lists
  humanURL: https://learn.microsoft.com/en-us/graph/azuread-identity-access-management-concept-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Groups
  properties:
  - type: OpenAPI
    url: openapi/microsoft-entra-groups-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/
  - type: Authentication
    url: https://learn.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-applications-basics
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview
- aid: microsoft-entra:microsoft-entra-serviceprincipals-api
  name: Microsoft Entra ServicePrincipals API
  description: Manage service principal objects that represent application instances in a tenant for authentication and authorization
  humanURL: https://learn.microsoft.com/en-us/graph/azuread-identity-access-management-concept-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - ServicePrincipals
  properties:
  - type: OpenAPI
    url: openapi/microsoft-entra-serviceprincipals-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/
  - type: Authentication
    url: https://learn.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-applications-basics
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview
- aid: microsoft-entra:microsoft-entra-users-api
  name: Microsoft Entra Users API
  description: Manage user accounts in the directory including creation, updates, profile management, and lifecycle operations
  humanURL: https://learn.microsoft.com/en-us/graph/azuread-identity-access-management-concept-overview
  baseURL: https://graph.microsoft.com/v1.0
  tags:
  - Users
  properties:
  - type: OpenAPI
    url: openapi/microsoft-entra-users-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/entra/identity/
  - type: Authentication
    url: https://learn.microsoft.com/en-us/graph/auth/
  - type: SDKs
    url: https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
  - type: Pricing
    url: https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/graph/tutorial-applications-basics
  - type: APIReference
    url: https://learn.microsoft.com/en-us/graph/api/resources/identity-network-access-overview
common:
- type: AgenticAccess
  url: agentic-access/microsoft-entra-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/microsoft-entra-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/microsoft-entra-domain-security.yml
- type: Authentication
  url: authentication/microsoft-entra-authentication.yml
- type: OAuthScopes
  url: scopes/microsoft-entra-scopes.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/microsoft-entra/overview
- type: Arazzo
  url: arazzo/microsoft-entra-audit-user-memberships-workflow.yml
  name: Microsoft Entra Audit User Memberships
- type: Arazzo
  url: arazzo/microsoft-entra-create-group-with-member-workflow.yml
  name: Microsoft Entra Create Group With Member
- type: Arazzo
  url: arazzo/microsoft-entra-create-m365-group-with-owner-member-workflow.yml
  name: Microsoft Entra Create Microsoft 365 Group With Member
- type: Arazzo
  url: arazzo/microsoft-entra-decommission-application-workflow.yml
  name: Microsoft Entra Decommission Application
- type: Arazzo
  url: arazzo/microsoft-entra-deprovision-user-workflow.yml
  name: Microsoft Entra Deprovision User
- type: Arazzo
  url: arazzo/microsoft-entra-find-and-update-application-workflow.yml
  name: Microsoft Entra Find And Update Application
- type: Arazzo
  url: arazzo/microsoft-entra-find-and-update-group-workflow.yml
  name: Microsoft Entra Find And Update Group
- type: Arazzo
  url: arazzo/microsoft-entra-find-and-update-user-workflow.yml
  name: Microsoft Entra Find And Update User
- type: Arazzo
  url: arazzo/microsoft-entra-grant-app-role-assignment-workflow.yml
  name: Microsoft Entra Grant App Role Assignment
- type: Arazzo
  url: arazzo/microsoft-entra-offboard-user-from-group-workflow.yml
  name: Microsoft Entra Offboard User From Group
- type: Arazzo
  url: arazzo/microsoft-entra-onboard-user-to-group-workflow.yml
  name: Microsoft Entra Onboard User To Group
- type: Arazzo
  url: arazzo/microsoft-entra-provision-user-workflow.yml
  name: Microsoft Entra Provision User
- type: Arazzo
  url: arazzo/microsoft-entra-register-app-with-service-principal-workflow.yml
  name: Microsoft Entra Register Application With Service Principal
- type: Arazzo
  url: arazzo/microsoft-entra-rotate-application-secret-workflow.yml
  name: Microsoft Entra Rotate Application Secret
- type: Portal
  url: https://entra.microsoft.com/
- type: GettingStarted
  url: https://learn.microsoft.com/en-us/entra/fundamentals/
- type: Blog
  url: https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity
- type: Support
  url: https://learn.microsoft.com/en-us/entra/fundamentals/how-to-get-support
- type: StatusPage
  url: https://status.azure.com/
- type: TermsOfService
  url: https://www.microsoft.com/licensing/terms/
- type: PrivacyPolicy
  url: https://privacy.microsoft.com/
- type: ChangeLog
  url: https://learn.microsoft.com/en-us/entra/fundamentals/whats-new
- type: SDKs
  url: https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
- type: GitHubOrganization
  url: https://github.com/microsoftgraph
- type: Authentication
  url: https://learn.microsoft.com/en-us/graph/auth/
- type: Pricing
  url: https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing
- type: JSONLD
  url: json-ld/microsoft-entra-context.jsonld
- type: JSONSchema
  url: json-schema/microsoft-entra-user-schema.json
- type: JSONSchema
  url: json-schema/microsoft-entra-application-schema.json
- type: Features
  data:
  - name: Identity and Access Management
    description: Manage user identities, authentication, and authorization across cloud and hybrid environments with single
      sign-on.
  - name: Conditional Access
    description: Enforce adaptive access policies based on user, device, location, and risk signals for zero trust security.
  - name: Identity Governance
    description: Automate access reviews, entitlement management, and lifecycle workflows to ensure proper access controls.
  - name: Privileged Identity Management
    description: Manage, control, and monitor privileged access with just-in-time and approval-based activation.
  - name: Verified ID
    description: Issue and verify decentralized identity credentials using open standards for portable, self-sovereign identity.
  - name: External Identities
    description: Enable secure collaboration with external partners and customers through B2B and B2C identity management.
  - name: Global Secure Access
    description: Provide identity-centric secure web gateway and zero-trust network access for internet and private resources.
  - name: Workload Identities
    description: Secure and manage identities for applications, services, scripts, and containers running as software workloads.
- type: UseCases
  data:
  - name: Zero Trust Implementation
    description: Implement zero trust architecture with identity-based access controls, conditional access policies, and continuous
      verification.
  - name: Hybrid Identity Management
    description: Synchronize and manage identities across on-premises Active Directory and cloud environments.
  - name: Application Single Sign-On
    description: Enable SSO for thousands of SaaS and on-premises applications with SAML, OIDC, and password-based authentication.
  - name: Automated User Provisioning
    description: Automate user lifecycle management with SCIM-based provisioning and deprovisioning across integrated applications.
  - name: AI Agent Identity Management
    description: Create, secure, and monitor identities for AI agents with authentication, authorization, and lifecycle management.
- type: Integrations
  data:
  - name: Microsoft 365
    description: Deep integration for identity and access management across all Microsoft 365 applications and services.
  - name: Azure Services
    description: Native identity provider for Azure resources including VMs, databases, storage, and managed identities.
  - name: Active Directory
    description: Hybrid identity synchronization with on-premises Active Directory using Azure AD Connect.
  - name: Salesforce
    description: SAML and SCIM integration for single sign-on and automated user provisioning with Salesforce.
  - name: ServiceNow
    description: SSO and automated provisioning integration with ServiceNow ITSM platform.
  - name: Workday
    description: Inbound provisioning from Workday HR to automate user lifecycle management.
  - name: SAP
    description: SSO and provisioning integration with SAP applications and S/4HANA.
  - name: Okta
    description: Cross-platform identity federation and migration support with Okta identity provider.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
  url: https://apievangelist.com/