Skip to main content
Connector guides

Connect Microsoft Graph

Microsoft Graph is how StackJack reaches Microsoft 365 and Entra ID — the users, groups, licences, devices, mailboxes, Teams, security alerts and Intune policies that make up most MSPs' daily work.…

Written By Christopher Scaminaci

Last updated About 22 hours ago

Microsoft Graph is how StackJack reaches Microsoft 365 and Entra ID — the users, groups, licences, devices, mailboxes, Teams, security alerts and Intune policies that make up most MSPs' daily work. Connecting it gives your AI a large set of graph_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack.

It is the sibling of the Microsoft Azure connector and shares the same sign-in, but it is a separate connection: Azure covers infrastructure and billing, Graph covers identity, devices and collaboration. Connecting one does not connect the other.

Nothing to enter, unless you bring your own app

Like Azure, this connector asks for no key, no secret and no URL by default. StackJack has its own Microsoft application, so you connect by signing in and approving the request — that is the entire setup. (Organizations that prefer to consent to an application they own can bring their own app registration instead — see Bring your own app registration below.)

  1. Check who can approve. Most of what this connector does needs a Global Administrator to approve it once, on behalf of everyone. If you are one, you can approve it yourself as you connect. If you are not, either ask an administrator to connect first, or ask them to approve the request when Microsoft prompts. A message saying approval is needed is Microsoft asking for that consent — it is not an error, and it is a one-time step for the whole organization.
  2. Connect with Microsoft. On the Connectors page, open Microsoft Graph and choose Connect with Microsoft. Sign in with the account you use for Microsoft 365 admin work and approve the request.
  3. Check what you can reach. Ask your AI to list your users. If something you expected is refused, that is usually a question about your own admin role rather than the connection — see below.

Your admin role decides what you can do

This is the most important thing to understand about this connector, and it is what separates StackJack from tools that connect to Microsoft 365 with a robot account.

Microsoft Graph checks two things on every call: the permissions you approved when connecting, and your own Microsoft 365 admin role. An action needs both. Approving the full list of permissions does not make you an administrator — a Helpdesk Administrator who approves everything still has a Helpdesk Administrator's reach, and will correctly be refused when they try to reset a Global Administrator's password.

That is the design, not a limitation, and it buys you three things:

  • Your existing least-privilege model keeps working. You do not have to trust an AI assistant with more access than the person using it already has.
  • The audit log names a real person. Every action in a customer's Microsoft 365 audit log shows the technician who performed it, not a shared service account. That is the record you would want to be accurate if a change is ever questioned.
  • Refusals are meaningful. When Graph refuses, it is enforcing your role correctly. Two people on the same team will legitimately get different answers from the same tool.

When something is refused, check your role first — it is the far more common cause and takes seconds to verify. Only if your role clearly covers the action is the permission the problem, and reconnecting re-runs consent to add anything newly required.

Managing your customers' Microsoft 365

If you manage customers through Microsoft's delegated access (GDAP), your USER access comes along automatically — there is no separate connection per customer. One thing does need setting up per customer, once: admin consent for the StackJack application in that customer's tenant (see the next section).

Every Graph tool takes an optional customer directory (their Microsoft tenant ID or a verified domain such as contoso.onmicrosoft.com). Leave it out and the tool works on your own tenant. Provide it and the tool works on that customer's, with whatever delegated access you already hold there.

GDAP answers "which PEOPLE may act in this customer's directory". Microsoft also asks a second, separate question on every call: "has this customer's tenant admitted the APPLICATION the call comes through?" GDAP roles do not answer it — the application must be admin-consented in the customer tenant, once. Until that happens, calls into that customer fail with a consent error (Microsoft's code AADSTS65001), and reconnecting your own sign-in will not fix it — consent is granted per tenant, not per user.

To grant it:

  1. On the Connectors page, open Microsoft Graph and use Authorize a customer tenant: enter the customer's tenant ID or a verified domain and generate the consent link.
  2. Send the link to an administrator in the customer's tenant. Any of these roles can approve it: Global Administrator, Application Administrator, or Cloud Application Administrator.
  3. They open the link, review the permissions, and approve. Allow a few minutes for Microsoft to propagate the consent, then the customer's tools work for every technician with GDAP access.

If Microsoft answers that multi-factor authentication is required (AADSTS50076): for GDAP access, MFA is enforced in your own partner tenant, at the Microsoft sign-in behind Connect with Microsoft, and the customer tenant always trusts it. A customer tenant cannot run its own MFA challenge for a GDAP user, so an MFA requirement is never fixed on the customer's side. Make sure the account is covered by MFA in your tenant, then reconnect Microsoft Graph from Connectors and complete the prompt.

If a consented customer tenant refuses for another reason: ask its admin to read the sign-in log entry for the reason code. A Conditional Access policy that blocks external accounts needs the specific partner accounts excluded from it.

In practice you just name the customer when you ask:

  • "List my delegated customers."
  • "Which users at Contoso have not signed in for 90 days?"
  • "Show me Contoso's Conditional Access policies."

Your access to a customer comes through a security group, not through your own admin role. If a customer's tools are refused while your own tenant works fine, the usual cause is that you personally are not in the group assigned to that customer — an admin in your partner tenant adds you to it. Being a Global Administrator in your own tenant grants nothing in theirs.

Every person signs in for themselves

There is no shared Microsoft Graph identity for a team to fall back on. The stored connection is one person's own Microsoft sign-in, carrying their admin roles and — where they hold delegated access — their reach into your customers' tenants, so StackJack will not run anyone else's calls under it.

  • Owners keep the fallback. The organization's owner and co-owners can use the stored connection before they personally sign in.
  • Everyone else must connect their own account, including Administrators. Until they do, Graph tools refuse for them with personal_sign_in_required. It is not a preference — it is the only way that member gets a Microsoft identity at all.
  • Nothing has to be prepared for them while the organization is on StackJack's own Microsoft application: a member can connect whether or not an owner ever configured the connector.

That is also what makes the per-person role model and the audit trail real. One shared identity would collapse the whole team's work onto one name and give everyone the reach of whoever set it up.

Members connect from the Connectors page, in their personal sign-ins section. The rules in full: Who can use which identity.

Bring your own app registration

Some organizations prefer to consent to an application they own — their name on the consent screen, their control over the app's permission list, their secret to rotate. StackJack supports that:

  1. Create the app in your tenant. StackJack ships a provisioning script that registers a multitenant Entra application carrying StackJack's redirect URLs and the delegated permission set for the tier you pick. You can equally build it by hand or push it with your own automation — the script prints everything the registration needs.
  2. Paste the credentials into StackJack. On the Connectors page, open Microsoft Graph → Advanced — use your own app registration, and enter the Application (client) ID and client secret. Once your organization is on its own application, reconnecting with these fields empty keeps that application. To return to StackJack's application, tick Switch back to the StackJack application on the next Connect — the option appears once the organization's shared connection is on a custom app — and connect again. If the option does not appear but your organization still connects under its own application, disconnect the connector and connect again with the fields empty. Disconnecting removes the organization's shared connection and un-links existing MCP keys from the connector, so plan it like any credential change. If you also tick the "remove its tools" box, the connector's tools stay off until the organization connects again — your own reconnect turns them back on automatically, but a team member's personal reconnect cannot. The switch changes the organization's shared connection; team members' sign-ins and agent credentials keep their current application until each is reconnected or re-enrolled. Each Microsoft connector card (Microsoft Graph and Microsoft Azure) stores its own application choice, so switch back on each card you use.
  3. Connect with Microsoft as usual. From then on every sign-in in your organization — yours, your teammates', your automations' — runs under your app. Customer-tenant consent links from Authorize a customer tenant name your app too.

Two things to plan for: your app must be multitenant if you manage customers through GDAP (single-tenant apps cannot be consented in a customer directory), and rotating your app's client secret invalidates existing sign-ins — update the secret in StackJack first, then each person reconnects.

Whether you use StackJack's application or your own, the connect flow lets you pick a permission tier for your organization:

  • Full (default) — every capability the connector ships.
  • Standard — everything except directory-privileged writes (role management, app registrations, Conditional Access policy writes, privileged device operations, and similar). The read-only forms of those same areas are still requested, so listing your delegated customers, your domains, your organization and your directory roles keeps working.
  • Read-only — the read-only form of every capability the connector ships. It is not a shorter list of the same permissions: where the connector normally asks to read and write your mail, this tier asks only to read it.

The tier sets what the Microsoft consent prompt asks for, and a tool that needs a permission nobody consented to fails with Microsoft's own permissions error instead of acting. Two things it does not do: it does not revoke permissions your organization already consented to, and it does not narrow a customer-tenant consent link — that link grants whatever the application's own registration lists. Start narrow if your organization is hesitant; you can re-connect on a wider tier later, and Microsoft prompts only for the newly added permissions.

The permissions each tier requests

The provisioning script looks every permission up in your own tenant while it runs, so it never prints a list you can copy out of it. The names are below for anyone who builds the app registration by hand, or who mirrors the same permission set in another tool. They are Microsoft's own delegated permission names, spelled exactly as the Entra portal spells them on an app registration's API permissions page.

Two things to read them with. A narrower tier is not a shorter version of a wider one — Standard and Read-only both ask for read permissions that Full never asks for, because at Full the matching write permission already covers the read. And the first four entries in every list (openid, profile, email, offline_access) are the sign-in permissions any connection needs; offline_access is the one that lets a connection keep working without sending you back to the sign-in page.

Full — 59 permissions

openid
profile
email
offline_access
User.Read
User.ReadWrite.All
Group.ReadWrite.All
Directory.ReadWrite.All
AdministrativeUnit.ReadWrite.All
AppRoleAssignment.ReadWrite.All
Directory.AccessAsUser.All
Device.Read.All
Application.ReadWrite.All
RoleManagement.ReadWrite.Directory
Policy.Read.All
Policy.ReadWrite.ConditionalAccess
Policy.ReadWrite.AuthenticationMethod
AuditLog.Read.All
Reports.Read.All
Organization.ReadWrite.All
Domain.ReadWrite.All
IdentityRiskyUser.ReadWrite.All
IdentityRiskEvent.Read.All
Mail.ReadWrite
Mail.Send
Calendars.ReadWrite
Files.ReadWrite.All
Sites.ReadWrite.All
MailboxSettings.ReadWrite
Contacts.ReadWrite
Mail.ReadWrite.Shared
Mail.Send.Shared
Calendars.ReadWrite.Shared
Contacts.ReadWrite.Shared
Team.ReadBasic.All
Channel.ReadBasic.All
ChannelMessage.Read.All
TeamMember.ReadWrite.All
Team.Create
TeamSettings.ReadWrite.All
Channel.Create
ChannelSettings.ReadWrite.All
ChannelMessage.Send
Chat.ReadWrite
Presence.Read.All
SecurityEvents.ReadWrite.All
SecurityAlert.ReadWrite.All
SecurityIncident.ReadWrite.All
ThreatHunting.Read.All
DeviceManagementManagedDevices.PrivilegedOperations.All
DeviceManagementManagedDevices.ReadWrite.All
DeviceManagementConfiguration.ReadWrite.All
DeviceManagementApps.ReadWrite.All
DeviceManagementServiceConfig.ReadWrite.All
DeviceManagementRBAC.Read.All
DeviceManagementRBAC.ReadWrite.All
DeviceManagementScripts.ReadWrite.All
DelegatedAdminRelationship.ReadWrite.All
UserAuthenticationMethod.ReadWrite.All

Standard — 54 permissions

openid
profile
email
offline_access
User.Read
User.ReadWrite.All
Group.ReadWrite.All
Directory.ReadWrite.All
AdministrativeUnit.ReadWrite.All
Device.Read.All
Policy.Read.All
AuditLog.Read.All
Reports.Read.All
IdentityRiskEvent.Read.All
Mail.ReadWrite
Mail.Send
Calendars.ReadWrite
Files.ReadWrite.All
Sites.ReadWrite.All
MailboxSettings.ReadWrite
Contacts.ReadWrite
Mail.ReadWrite.Shared
Mail.Send.Shared
Calendars.ReadWrite.Shared
Contacts.ReadWrite.Shared
Team.ReadBasic.All
Channel.ReadBasic.All
ChannelMessage.Read.All
TeamMember.ReadWrite.All
Team.Create
TeamSettings.ReadWrite.All
Channel.Create
ChannelSettings.ReadWrite.All
ChannelMessage.Send
Chat.ReadWrite
Presence.Read.All
SecurityEvents.ReadWrite.All
SecurityAlert.ReadWrite.All
SecurityIncident.ReadWrite.All
ThreatHunting.Read.All
DeviceManagementManagedDevices.ReadWrite.All
DeviceManagementConfiguration.ReadWrite.All
DeviceManagementApps.ReadWrite.All
DeviceManagementServiceConfig.ReadWrite.All
DeviceManagementRBAC.Read.All
DeviceManagementRBAC.ReadWrite.All
DeviceManagementScripts.ReadWrite.All
RoleManagement.Read.Directory
Application.Read.All
UserAuthenticationMethod.Read.All
IdentityRiskyUser.Read.All
Domain.Read.All
Organization.Read.All
DelegatedAdminRelationship.Read.All

The last seven are the read permissions this tier adds back for the privileged writes it drops, so that listing your delegated customers, your domains, your organization, your directory roles and your risky users keeps working.

Read-only — 47 permissions

openid
profile
email
offline_access
User.Read
User.Read.All
Group.Read.All
Directory.Read.All
AdministrativeUnit.Read.All
Device.Read.All
Application.Read.All
RoleManagement.Read.Directory
Policy.Read.All
AuditLog.Read.All
Reports.Read.All
Organization.Read.All
Domain.Read.All
IdentityRiskyUser.Read.All
IdentityRiskEvent.Read.All
Mail.Read
Calendars.Read
Files.Read.All
Sites.Read.All
MailboxSettings.Read
Contacts.Read
Mail.Read.Shared
Calendars.Read.Shared
Contacts.Read.Shared
Team.ReadBasic.All
Channel.ReadBasic.All
ChannelMessage.Read.All
TeamMember.Read.All
TeamSettings.Read.All
ChannelSettings.Read.All
Chat.Read
Presence.Read.All
SecurityEvents.Read.All
SecurityAlert.Read.All
SecurityIncident.Read.All
ThreatHunting.Read.All
DeviceManagementManagedDevices.Read.All
DeviceManagementConfiguration.Read.All
DeviceManagementApps.Read.All
DeviceManagementServiceConfig.Read.All
DeviceManagementRBAC.Read.All
DelegatedAdminRelationship.Read.All
UserAuthenticationMethod.Read.All

Microsoft Azure asks for the same one permission on every tier. That connector requests a single delegated permission — https://management.azure.com/user_impersonation — alongside the four sign-in permissions, and the tier you pick changes nothing about it. Azure publishes only that one permission, and what you can actually reach through it is decided by your own Azure role assignments rather than by anything consented here.

Working in a shared mailbox

Mail, calendar and contact tools act on your own mailbox by default. Most of them also accept a shared or delegated mailbox address — support@contoso.com, a reception calendar, a departmental address book — and act there instead.

This needs two things, and StackJack can only supply one of them. Connecting grants the Microsoft permission. The second half is Exchange delegate access to that specific mailbox, granted per mailbox by its owner or by an Exchange administrator: Full Access to read and manage its contents, and Send As or Send on Behalf to send from it. No Microsoft Entra admin role gives you this — not even Global Administrator. If a tool reports that access was denied for a shared mailbox, that grant is almost always what is missing, and the fix is in the Exchange admin centre rather than here.

Sending from a shared mailbox works too, and it is worth knowing which name recipients will see. That depends on the Exchange permission you hold, not on anything set here:

  • Send As — the message appears to come from the shared mailbox itself. Nothing indicates who actually sent it.
  • Send on Behalf — the message shows as sent by you on behalf of the shared mailbox.

If you hold neither, sending is refused even though reading works, which is the usual explanation when a shared mailbox can be read but not sent from.

One limit worth knowing before you plan around it:

  • Mailbox settings are always your own. Out-of-office replies, Outlook categories and inbox rules read and write your mailbox regardless of what else you ask for. Microsoft publishes no shared equivalent for these, so this one is not a matter of asking for more access — there is nothing to ask for.

Calendars work more completely: everything including accepting, declining, forwarding and cancelling meetings can be done in a calendar shared with you. Free/busy lookups are the exception and always run from your own account — they read other people by name rather than by opening their calendar.

What this connector deliberately does not do

Stated up front so it does not read as a gap. Most of these are statements about the purpose-built tools; the raw request tools described below reach further, with the same consent and the same Entra role.

  • It has no tools for the Exchange Online admin surface. Transport rules, mail-flow connectors, retention policies and mailbox permissions beyond what Graph exposes are not part of Microsoft Graph at all — they need Exchange's own administration interface, and no raw request reaches them either. This is the largest honest gap in Microsoft 365 coverage and is worth knowing about rather than discovering.
  • It has no tools for Microsoft Purview / compliance — eDiscovery, DLP policies, retention labels and insider risk. Where Graph publishes these, a raw request can reach them.
  • It has no tools for Planner, To Do, Viva, Bookings or the Excel workbook API. Those are end-user productivity surfaces rather than tenant management. They are on Graph, so a raw request can reach them.
  • It does not cover Microsoft 365 Government or the 21Vianet cloud in China. Those are separate clouds needing their own setup, and Microsoft's delegated-access APIs are unavailable in the China cloud regardless.
  • The purpose-built tools use only Microsoft's generally available v1.0 endpoint, so a Microsoft preview change cannot break an automation built on them. The most-missed consequence is Intune scripts: platform scripts, shell scripts and proactive remediations are still preview-only in Microsoft's API, so no tool covers them. The raw request tools are the exception and can be pointed at the beta endpoint deliberately — read the warning about that below before you build on it. Microsoft promoting an API to v1.0 does not, on its own, create a purpose-built tool for it, and it does not change what your organization has consented to.
  • It does not watch for changes. Tools answer questions when asked; there are no subscriptions to Microsoft change notifications.
  • It does not give automations access by default. An automation has no signed-in person of its own, so it cannot borrow your connection. If you want one to work in Microsoft 365, an administrator enrols a dedicated sign-in for that specific automation — see below.

Letting an automation use Microsoft 365

An automation can be given its own Microsoft connection, enrolled per automation by someone with agent-configuration access. It is worth understanding exactly what that means before doing it, because it is the one place where this connector's per-person model needs a deliberate decision rather than following automatically.

The automation acts as whichever Microsoft account was signed in during enrolment, with that account's admin role, and — if that account holds delegated access — in your customers' tenants too. So the choice of account is the choice of how much an unattended process can reach. Two practices worth following:

  • Enrol a dedicated account rather than a person's. A purpose-made account with only the roles that automation needs keeps the blast radius honest, and keeps the audit trail readable — actions show up under a name that means "this automation" rather than under a technician who was not at their desk.
  • Give the automation only the tools it needs. Sending mail and wiping devices are real actions with real recipients and real hardware; an automation that never needs them should not be offered them.

Removing an automation's connection revokes it immediately and does not affect anyone's personal connection.

Things that catch people out

A tool says approval is required. That is Microsoft asking for tenant-wide admin consent, not a failure. One Global Administrator approves once and everyone can connect afterwards.

A query is rejected as unsupported. Graph splits filtering into a basic set and an advanced set, and refuses an advanced expression sent as a basic one. The usual triggers are "starts with" or "ends with" matching, a not-equals, or filtering and sorting in the same request. Simplify — filter or sort, not both — or use a search instead, which StackJack always sends in the advanced form.

Large lists come back partial. StackJack caps a single call at 1,000 items across 10 pages and tells your AI where the list left off so it can continue. This is a StackJack safety limit rather than a Microsoft one.

Two areas throttle much harder than the rest. Conditional Access and Identity Protection allow about one request per second for your entire tenant, shared with every other tool you run, and the sign-in and audit reports are nearly as tight. Ask about those one page at a time rather than sweeping. Throttling is temporary, clears on its own, and never counts toward disabling your connection.

Destructive actions

Some Graph tools reach real people, lock someone out, or change who has access. StackJack marks those as destructive and they are all Pro-tier. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and restrict the tools you grant, before you allow destructive Graph actions.

The sharpest ones are worth knowing by name:

  • Sending, replying to or forwarding mail delivers a real message to real recipients and cannot be recalled. It goes from your own mailbox by default, or from a shared mailbox you have Send As or Send on Behalf rights to — in which case the recipients may see the mailbox's name rather than yours.
  • Wiping or retiring a device factory-resets or unenrolls a customer's endpoint as soon as it next checks in, with no undo from here.
  • Resetting a password or revoking sign-in sessions locks a human out of their work until they are helped back in.
  • Adding an application password or key mints a working credential that can be used from anywhere.
  • Changing a Conditional Access policy can lock an entire tenant out, including you.
  • Granting a directory role, an Intune role, or a delegated-access assignment changes the access-control boundary itself. Intune role changes are worth singling out: an Intune role assignment names both who gets the role and which devices they may act on, and updating one replaces both lists rather than adding to them.
  • Disabling or deleting a device stops that machine passing Conditional Access, so the person using it loses access to their work accounts with nothing on screen to explain why. Deleting the device record also takes its BitLocker recovery keys with it — read those out first if the disk is encrypted.
  • Archiving a team or a channel makes it read-only for everyone at once, with no notice to its members.

Marking these clearly is what lets the rest of the connector be used freely.

Advanced: raw API requests

Reach for a purpose-built tool first. They escape the identifiers you pass, add the headers Graph needs, cap the page size, and their descriptions say what the answer means. Use the raw tools only where no purpose-built tool exists.

Two tools send a request you compose straight to Microsoft Graph:

  • graph_raw_get sends one GET. It is Free-tier and read-only.
  • graph_raw_request sends one POST, PUT, PATCH or DELETE. It is Pro-tier and marked destructive. It refuses GET, so a read cannot be run through the write tool.

What they change, and what they do not:

  • They widen coverage, not permission. Your connector subscription, your endpoint's tool selection, your plan and your monthly allowance all still apply. Graph still authorizes each call on the overlap between what your organization consented to and your own Entra role, so a raw request returns exactly what you could reach anyway.
  • They are the only way to reach Microsoft's beta endpoint. Every purpose-built tool is pinned to v1.0. Beta is not a newer v1.0: Microsoft documents it as subject to change without notice and not for production use, and properties appear and disappear between releases. An automation built on a beta shape breaks quietly when Microsoft changes it. Use v1.0 unless the data exists only on beta.
  • Paging is yours to drive. A continuation link comes back in the body; pass it back to get the next page. Nothing pages for you.
  • Advanced queries need a header these tools do not add. Graph's advanced filtering requires a consistency header, and the raw tools send none. Use the purpose-built tool that knows to add it.
  • A merging write clears what you set to null. PATCH on Graph leaves out properties alone, while an explicit null empties them. Only the body distinguishes the two.
  • Some surfaces refuse a raw write outright. The delegated-access relationship and assignment writes require a concurrency header that these tools do not send, so use the purpose-built tools there.
  • Most write responses come back empty. Graph answers many actions with an acceptance and no body, which arrives as {}. That is not a failure and it is not proof of completion — read the object back to confirm.
  • The path is fenced. It is relative to the version segment, with no scheme, no directory traversal and no version segment of its own. Anything else is refused before the request is sent.

See the generated Microsoft Graph tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Microsoft Graph tools

graph_ · 530 tools · Free 284 · Pro 246

Users

ToolWhat it does
graph_assign_user_license
Pro · Write
Assign one or more Microsoft 365 licences to a user.
graph_create_user
Pro · Write
Create a new user account.
graph_delete_user
Pro · Destructive
Delete a user account.
graph_get_signed_in_user
Free · Read-only
Get the profile of the person whose Microsoft sign-in this connection was made with — the account StackJack is acting as.
graph_get_user
Free · Read-only
Get one user account in full, by object id or user principal name (their sign-in address).
graph_get_user_manager
Free · Read-only
Get the person recorded as a user's manager.
graph_list_deleted_users
Free · Read-only
List user accounts that have been deleted but are still recoverable.
graph_list_inactive_users
Free · Read-only
List users together with their last sign-in and last non-interactive sign-in times — the licence-reclamation and offboarding-audit read.
graph_list_user_app_role_assignments
Free · Read-only
List the enterprise applications a user has been assigned to, and the role they hold in each.
graph_list_user_devices
Free · Read-only
List the devices registered to a user in the directory — the machines and phones their identity is attached to.
graph_list_user_direct_reports
Free · Read-only
List the people who report to a user.
graph_list_user_groups
Free · Read-only
List the groups, directory roles and administrative units a user belongs to DIRECTLY.
graph_list_user_licenses
Free · Read-only
List the Microsoft 365 licences assigned to one user, with the individual service plans inside each and whether each is enabled or switched off.
graph_list_user_owned_objects
Free · Read-only
List the directory objects a user owns — groups, application registrations and service principals.
graph_list_user_transitive_groups
Free · Read-only
List every group a user belongs to INCLUDING the ones reached through nested groups — their effective membership.
graph_list_users
Free · Read-only
List the user accounts in an Entra ID (Azure AD) directory — the starting point for almost any question about who works somewhere.
graph_permanently_delete_user
Pro · Destructive
Permanently remove a deleted user from the directory's recycle bin, ending the 30-day recovery window immediately.
graph_remove_user_license
Pro · Destructive
Remove one or more Microsoft 365 licences from a user.
graph_remove_user_manager
Pro · Destructive
Clear the manager relationship on a user, leaving them with none.
graph_reset_user_password
Pro · Destructive
Set a new password on a user account.
graph_restore_deleted_user
Pro · Write
Restore a user account from the directory's recycle bin, within the 30-day window.
graph_revoke_user_sign_in_sessions
Pro · Destructive
Invalidate every refresh token and session cookie a user holds, forcing them to sign in again everywhere — browsers, Outlook, Teams, phones.
graph_set_user_account_enabled
Pro · Destructive
Enable or disable a user's account — the standard first step of an offboarding, and the standard containment step for a compromised one.
graph_set_user_manager
Pro · Write
Set or replace the person recorded as a user's manager.
graph_update_user
Pro · Write
Update a user's profile details — display name, job title, department, office, phone numbers, usage location.

Groups

ToolWhat it does
graph_add_group_member
Pro · Write
Add a user, device, service principal or another group to a group.
graph_add_group_owner
Pro · Write
Add an owner to a group.
graph_create_group
Pro · Write
Create a security group or a Microsoft 365 group.
graph_delete_group
Pro · Destructive
Delete a group.
graph_get_group
Free · Read-only
Get one group in full by object id, including its kind, description, mail address, visibility, expiry date and — for a dynamic group — the membership rule that decides who is in it.
graph_list_deleted_groups
Free · Read-only
List groups that have been deleted but are still recoverable.
graph_list_group_app_role_assignments
Free · Read-only
List the enterprise applications a group is assigned to, and the role it holds in each.
graph_list_group_members
Free · Read-only
List the DIRECT members of a group — the users, other groups, devices and service principals added to it explicitly.
graph_list_group_memberships
Free · Read-only
List the groups and directory roles that a GROUP is itself a member of — the upward view of nesting.
graph_list_group_owners
Free · Read-only
List the owners of a group — the people who can manage its membership and settings without being directory administrators.
graph_list_group_transitive_members
Free · Read-only
List everyone who is effectively a member of a group, flattening every level of nesting.
graph_list_groups
Free · Read-only
List the groups in an Entra ID directory — security groups, Microsoft 365 groups and distribution lists.
graph_permanently_delete_group
Pro · Destructive
Permanently remove a deleted group from the recycle bin, ending the 30-day recovery window immediately.
graph_remove_group_member
Pro · Destructive
Remove a member from a group.
graph_remove_group_owner
Pro · Destructive
Remove an owner from a group.
graph_renew_group
Pro · Write
Renew a Microsoft 365 group, restarting its expiration clock.
graph_restore_deleted_group
Pro · Write
Restore a group from the directory's recycle bin, within the 30-day window.
graph_update_group
Pro · Write
Update a group's name, description or visibility.
graph_update_group_dynamic_membership_rule
Pro · Destructive
Change the rule that decides who belongs to a dynamic group.

Delegated Admin (GDAP)

ToolWhat it does
graph_approve_delegated_admin_relationship
Pro · Write
Approve a GDAP relationship that an indirect provider created for you as an indirect reseller.
graph_create_delegated_admin_access_assignment
Pro · Destructive
Grant one of the partner's security groups a set of administrative roles inside a customer's tenant.
graph_create_delegated_admin_relationship
Pro · Write
Create a GDAP relationship request for a customer.
graph_delete_delegated_admin_access_assignment
Pro · Destructive
Remove an access assignment, revoking that partner group's administrative roles in the customer's tenant.
graph_delete_delegated_admin_relationship
Pro · Destructive
Delete a GDAP relationship outright.
graph_get_delegated_admin_access_assignment
Free · Read-only
Get one GDAP access assignment, naming the partner security group it is built on and the exact customer roles that group receives.
graph_get_delegated_admin_customer
Free · Read-only
Get one delegated-admin customer by id, with its display name and tenant id.
graph_get_delegated_admin_relationship
Free · Read-only
Get one GDAP relationship in full, including the exact set of Entra role definition ids it grants, its activation and end dates, and whether it auto-extends.
graph_get_delegated_admin_relationship_operation
Free · Read-only
Get one long-running GDAP operation by id and see whether it succeeded, is still running, or failed and why.
graph_get_delegated_admin_relationship_request
Free · Read-only
Get one GDAP relationship request by id, with the action it carried and its outcome.
graph_list_delegated_admin_access_assignments
Free · Read-only
List the access assignments on one GDAP relationship — which of the partner's own security groups holds which of the customer's Entra roles.
graph_list_delegated_admin_customer_service_management_details
Free · Read-only
List the service-management links for one delegated-admin customer — the per-workload administration URLs (Exchange, Teams, SharePoint and the rest) that open that customer's admin centre directly.
graph_list_delegated_admin_customers
Free · Read-only
List the customers this partner can administer, as the delegated-admin surface sees them.
graph_list_delegated_admin_relationship_operations
Free · Read-only
List the long-running operations on one GDAP relationship.
graph_list_delegated_admin_relationship_requests
Free · Read-only
List the requests raised against one GDAP relationship — the lock-for-approval, approve, reject and terminate actions and how each of them finished.
graph_list_delegated_admin_relationships
Free · Read-only
List every GDAP relationship this partner tenant holds — one per customer per grant, with the roles it carries, its duration and its status.
graph_lock_delegated_admin_relationship_for_approval
Pro · Write
Finalize a draft GDAP relationship and lock it for the customer's approval, moving it from "created" to "approvalPending".
graph_reject_delegated_admin_relationship
Pro · Destructive
Reject a pending GDAP relationship that an indirect provider created for you as an indirect reseller.
graph_terminate_delegated_admin_relationship
Pro · Destructive
End an active GDAP relationship.
graph_update_delegated_admin_access_assignment
Pro · Destructive
Replace the set of customer roles an existing access assignment grants.
graph_update_delegated_admin_relationship
Pro · Write
Update a GDAP relationship's name, duration, requested roles or auto-extension.

Licensing

ToolWhat it does
graph_assign_group_license
Pro · Write
Assign licence SKUs to a group, so every member receives them automatically.
graph_get_group_license_assignment
Free · Read-only
Get the licences assigned to a group and the current state of applying them to its members.
graph_get_subscribed_sku
Free · Read-only
Get one purchased SKU in full, including every service plan it contains and each plan's provisioning status.
graph_get_user_license_assignment_states
Free · Read-only
Get the per-SKU assignment state for one user — where each licence came from, whether it applied cleanly, and the exact error when it did not.
graph_list_subscribed_skus
Free · Read-only
List every licence SKU the tenant has bought, with how many units were purchased, how many are assigned and how many remain.
graph_list_users_with_license
Free · Read-only
List everyone assigned a particular licence SKU.
graph_remove_group_license
Pro · Destructive
Remove licence SKUs from a group, which unlicenses every member who was relying on that group for them.
graph_reprocess_user_license_assignment
Pro · Write
Re-evaluate a user's group-based licence assignments.

Organization & Domains

ToolWhat it does
graph_create_domain
Pro · Write
Add a DNS domain to the tenant.
graph_delete_domain
Pro · Destructive
Remove a domain from the tenant.
graph_force_delete_domain
Pro · Destructive
Delete a domain even though objects still reference it, by RENAMING every referencing user and group onto the tenant's initial onmicrosoft.com domain first — and, unless told otherwise, disabling those user accounts.
graph_get_domain
Free · Read-only
Get one domain in full.
graph_get_domain_root_domain
Free · Read-only
Get the root domain a subdomain hangs off.
graph_get_organization
Free · Read-only
Get the tenant's own organization record — display name, postal address, contact emails, preferred language, default usage location, every verified domain, and the service plans the tenant is entitled to.
graph_get_organization_branding
Free · Read-only
Get the company branding applied to the tenant's sign-in experience — background image and colour, banner logo, sign-in page text, username hint and the self-service password reset links.
graph_list_certificate_based_auth_configurations
Free · Read-only
List the tenant's certificate-based authentication configuration — the trusted certificate authorities that let users sign in with a smart card or client certificate instead of a password.
graph_list_domain_name_references
Free · Read-only
List the users, groups and applications whose identity references a domain.
graph_list_domain_service_configuration_records
Free · Read-only
Get the DNS records that make Microsoft 365 services actually work on a verified domain — the MX record mail delivery depends on, the SPF TXT record that stops the tenant's own mail being marked as spam, and the CNAME and SRV records Teams and Skype signalling need.
graph_list_domain_verification_dns_records
Free · Read-only
Get the DNS records that must be published in a domain's zone file BEFORE ownership can be verified.
graph_list_domains
Free · Read-only
List every DNS domain associated with the tenant, with the four flags that answer most domain questions at a glance: isVerified says whether ownership was proven, isDefault marks the domain new users are created under, isInitial marks the permanent onmicrosoft.com domain Microsoft issued and which can never be deleted, and isRoot distinguishes a root domain from a subdomain.
graph_list_group_setting_templates
Free · Read-only
List the setting templates Entra publishes, each naming the settings it contains, their types and their default values.
graph_list_group_settings
Free · Read-only
List the tenant-wide directory settings currently in force — despite the endpoint's name these are not per-group settings but organization-wide policy, and they are where several answers live that people expect to find elsewhere: whether members may invite guests, whether ordinary users may create Microsoft 365 groups, the group naming and blocked-word policy, and the custom banned password list.
graph_list_organization_branding_localizations
Free · Read-only
List the per-language overrides of the tenant's sign-in branding.
graph_promote_domain
Pro · Destructive
Promote a verified subdomain to be a root domain in its own right, so it stops inheriting authentication settings from its parent and carries its own.
graph_update_domain
Pro · Write
Update a verified domain's supported services, password policy or default status.
graph_update_group_setting
Pro · Write
Update a tenant-wide directory settings object — guest invitation policy, who may create Microsoft 365 groups, the group naming policy, the banned password list.
graph_update_organization
Pro · Write
Update the tenant's organization record — the notification addresses Microsoft uses to reach the customer, the postal address, and the preferred language.
graph_verify_domain
Pro · Write
Prove ownership of a domain by having Entra look for the verification record in its public DNS.

Applications & Service Principals

ToolWhat it does
graph_add_application_key
Pro · Destructive
Add a certificate credential to an app registration, for rolling an expiring certificate without downtime.
graph_add_application_owner
Pro · Write
Add a user as an owner of an app registration.
graph_add_application_password
Pro · Destructive
Generate a new client secret for an app registration and return its value.
graph_add_service_principal_key
Pro · Destructive
Add a certificate credential to a service principal, for rolling an expiring certificate.
graph_add_service_principal_owner
Pro · Write
Add a user as an owner of a service principal.
graph_add_service_principal_password
Pro · Destructive
Generate a new client secret on a service principal and return its value — the same one-time disclosure as the app-registration version, and the same warning: this response is the only time Microsoft ever shows the secret.
graph_create_application
Pro · Write
Register a new application in this directory.
graph_create_delegated_grant
Pro · Destructive
Consent to delegated permissions for a client application, on behalf of one user or of everyone in the tenant.
graph_create_service_principal
Pro · Write
Create a service principal for an application in this directory — giving an existing app registration an identity here so it can sign in and be assigned access.
graph_delete_application
Pro · Destructive
Delete an app registration into the 30-day recycle bin, where it can be restored with its object id, client id and credentials intact.
graph_delete_delegated_grant
Pro · Destructive
Revoke a delegated permission grant entirely.
graph_delete_service_principal
Pro · Destructive
Delete an application's identity in this tenant, taking its consent grants and role assignments with it.
graph_get_application
Free · Read-only
Get one app registration in full: its redirect URIs, the API permissions it requests, its credentials and their expiry dates, and whether it is single- or multi-tenant.
graph_get_service_principal
Free · Read-only
Get one service principal in full — an application's identity inside this specific tenant.
graph_grant_app_role_assignment
Pro · Destructive
Assign an app role on a resource application to a user, group or service principal.
graph_list_application_owners
Free · Read-only
List the owners of an app registration — the people who can change it, add credentials to it and consent on its behalf without holding any directory role.
graph_list_applications
Free · Read-only
List the app registrations defined in this directory — the applications the tenant itself owns, not the third-party apps it merely uses.
graph_list_delegated_grants
Free · Read-only
List every delegated permission grant in the directory — the tenant-wide consent inventory.
graph_list_deleted_applications
Free · Read-only
List app registrations in the 30-day recycle bin.
graph_list_service_principal_app_role_assigned_to
Free · Read-only
List the app-role assignments made ON this service principal — who has been given a role in this application.
graph_list_service_principal_app_role_assignments
Free · Read-only
List the app-role assignments GRANTED TO this service principal — the application permissions it holds against other APIs, such as Mail.Read or Directory.ReadWrite.All over the whole tenant.
graph_list_service_principal_delegated_grants
Free · Read-only
List the delegated permission grants for one client application — what it may do on behalf of a signed-in user.
graph_list_service_principal_owners
Free · Read-only
List the owners of a service principal.
graph_list_service_principals
Free · Read-only
List the service principals in a directory — every application that has an identity in this tenant, including Microsoft's own first-party services and every third-party app anyone has consented to.
graph_permanently_delete_application
Pro · Destructive
Permanently remove a deleted app registration from the recycle bin.
graph_remove_application_key
Pro · Destructive
Remove a certificate credential from an app registration.
graph_remove_application_owner
Pro · Destructive
Remove an owner from an app registration.
graph_remove_application_password
Pro · Destructive
Delete a client secret from an app registration by its keyId.
graph_remove_service_principal_key
Pro · Destructive
Remove a certificate credential from a service principal.
graph_remove_service_principal_owner
Pro · Destructive
Remove an owner from a service principal.
graph_remove_service_principal_password
Pro · Destructive
Delete a client secret from a service principal by its keyId.
graph_restore_deleted_application
Pro · Write
Restore an app registration from the 30-day recycle bin.
graph_revoke_app_role_assignment
Pro · Destructive
Remove an app-role assignment, revoking that access.
graph_set_service_principal_enabled
Pro · Destructive
Turn an application's sign-in on or off in this tenant.
graph_update_application
Pro · Write
Update an app registration's properties.
graph_update_delegated_grant
Pro · Destructive
Replace the scopes on an existing delegated permission grant.
graph_update_service_principal
Pro · Write
Update a service principal's local properties — its display name in this tenant, its notes, its home-page URL, its tags.

Directory Roles & PIM

ToolWhat it does
graph_activate_directory_role
Pro · Write
Activate a directory role in this tenant from its template, creating the role object so members can be added to it.
graph_activate_eligible_role
Pro · Destructive
Activate a role the signed-in user is already eligible for — the just-in-time elevation at the centre of Privileged Identity Management.
graph_add_directory_role_member
Pro · Destructive
Add a user, group or service principal to a directory role, granting that role's administrative permissions permanently and immediately.
graph_assign_role_with_schedule
Pro · Destructive
Assign a directory role through Privileged Identity Management with a time limit — an ACTIVE grant that expires on its own.
graph_create_role_assignment
Pro · Destructive
Create a unified RBAC role assignment — the way to grant a role SCOPED to part of the directory rather than all of it.
graph_create_role_definition
Pro · Write
Create a custom directory role from a set of resource actions.
graph_deactivate_eligible_role
Pro · Write
Give up a role the signed-in user activated, before it expires on its own.
graph_delete_role_assignment
Pro · Destructive
Remove a unified RBAC role assignment, revoking those permissions immediately.
graph_delete_role_definition
Pro · Destructive
Delete a custom role definition.
graph_get_directory_role
Free · Read-only
Get one activated directory role by its object id, including the roleTemplateId that identifies WHICH Entra role it is.
graph_get_role_definition
Free · Read-only
Get one role definition with its full permission set.
graph_get_role_management_policy
Free · Read-only
Get one PIM policy, expanding its rules — which is where the settings that matter actually live.
graph_list_directory_role_members
Free · Read-only
List who holds a directory role.
graph_list_directory_role_templates
Free · Read-only
List every directory role Entra defines, whether or not this tenant has ever used one.
graph_list_directory_roles
Free · Read-only
List the directory roles that are ACTIVE in this tenant.
graph_list_role_assignment_instances
Free · Read-only
List the role assignments in effect right NOW — the closest thing this API offers to "who is an administrator at this moment".
graph_list_role_assignment_requests
Free · Read-only
List the requests that assigned, activated, extended or removed role assignments — the PIM audit trail, including every self-activation with the justification the person typed.
graph_list_role_assignment_schedules
Free · Read-only
List the scheduled role ASSIGNMENTS — active grants managed through Privileged Identity Management, including the ones with an expiry date.
graph_list_role_assignments
Free · Read-only
List unified RBAC role assignments — the permanent grants, including the SCOPED ones that the directory-role member listing cannot express.
graph_list_role_definitions
Free · Read-only
List the unified RBAC role definitions — every built-in Entra role plus any custom roles this tenant has defined, each with the exact permissions it carries in rolePermissions.
graph_list_role_eligibility_instances
Free · Read-only
List the role eligibilities that are in effect right NOW, as opposed to the schedules that define them.
graph_list_role_eligibility_requests
Free · Read-only
List the requests that created, changed or removed role eligibilities — the audit trail for who was made eligible for what, by whom, and with what justification.
graph_list_role_eligibility_schedules
Free · Read-only
List who is ELIGIBLE for a directory role — the people who can elevate themselves into it whenever they choose, without asking anyone.
graph_list_role_management_policies
Free · Read-only
List the Privileged Identity Management policies for directory roles — the rules that decide how elevation actually works: whether approval is required, whether multifactor authentication is enforced at activation, how long an activation lasts, and who gets notified.
graph_list_role_management_policy_assignments
Free · Read-only
List which PIM policy applies to which role.
graph_make_principal_eligible_for_role
Pro · Destructive
Make a user or group ELIGIBLE for a directory role through Privileged Identity Management — they hold nothing until they activate, and can activate whenever they choose subject to the role's PIM policy.
graph_remove_directory_role_member
Pro · Destructive
Remove a member from a directory role, revoking those administrative permissions immediately.
graph_remove_role_eligibility
Pro · Destructive
Remove someone's eligibility for a directory role, so they can no longer elevate into it.
graph_remove_scheduled_role_assignment
Pro · Destructive
Remove a role assignment that was made through Privileged Identity Management, revoking it immediately rather than waiting for it to expire.
graph_update_role_definition
Pro · Destructive
Update a custom role definition.

Authentication Methods

ToolWhat it does
graph_add_user_email_method
Pro · Destructive
Register an email address on an account for self-service password reset.
graph_add_user_phone_method
Pro · Destructive
Register a phone number for multifactor authentication on an account.
graph_create_temporary_access_pass
Pro · Destructive
Issue a Temporary Access Pass for a user and RETURN THE PASSCODE.
graph_delete_temporary_access_pass
Pro · Destructive
Revoke a Temporary Access Pass immediately, before it expires on its own.
graph_delete_user_authenticator_method
Pro · Destructive
Remove a Microsoft Authenticator registration from an account — the standard lost-phone and replaced-phone action.
graph_delete_user_email_method
Pro · Destructive
Remove an email address from an account's password-reset methods.
graph_delete_user_fido2_method
Pro · Destructive
Remove a FIDO2 security key from an account.
graph_delete_user_phone_method
Pro · Destructive
Remove a phone number from an account's authentication methods.
graph_delete_user_software_oath_method
Pro · Destructive
Remove a third-party authenticator (software OATH) token from an account.
graph_delete_user_windows_hello_method
Pro · Destructive
Remove a Windows Hello for Business registration from an account.
graph_disable_user_sms_sign_in
Pro · Destructive
Stop a user signing in with an SMS code, leaving the number registered as a second factor.
graph_enable_user_sms_sign_in
Pro · Destructive
Allow a user to sign IN with a code sent to their registered mobile number, rather than only using it as a second factor.
graph_get_authentication_methods_policy
Free · Read-only
Get the tenant's authentication methods policy — which methods are permitted, and for whom.
graph_list_authentication_method_registrations
Free · Read-only
List every user's authentication-method registration status in one report — who is registered for multifactor authentication, who is capable of self-service password reset, and which methods each has.
graph_list_user_authentication_methods
Free · Read-only
List every authentication method registered on one account, of every type, in a single call.
graph_list_user_authenticator_methods
Free · Read-only
List the Microsoft Authenticator registrations on an account, including the device each one is installed on.
graph_list_user_email_methods
Free · Read-only
List the email addresses registered on an account for self-service password reset.
graph_list_user_fido2_methods
Free · Read-only
List the FIDO2 security keys registered on an account, with each key's model and the display name its owner gave it.
graph_list_user_phone_methods
Free · Read-only
List the phone numbers registered for multifactor authentication on one account, each with its type — mobile, alternateMobile or office.
graph_list_user_software_oath_methods
Free · Read-only
List the third-party authenticator (software OATH) tokens registered on an account — the codes generated by apps other than Microsoft Authenticator.
graph_list_user_temporary_access_passes
Free · Read-only
List the Temporary Access Passes on an account, with each one's lifetime, whether it is single-use, and whether it is currently usable.
graph_list_user_windows_hello_methods
Free · Read-only
List the Windows Hello for Business registrations on an account — the PIN or biometric sign-in bound to a specific device.
graph_reset_user_password_generated
Pro · Destructive
Ask Entra to generate a new password for a user and RETURN IT.
graph_set_authentication_method_configuration
Pro · Destructive
Turn an authentication method on or off for the whole tenant, or restrict it to particular groups.
graph_update_authentication_methods_policy
Pro · Destructive
Update the tenant-wide authentication methods policy — the settings that sit above the individual methods, most usefully the registration campaign that nudges users onto the Authenticator app and the policy's migration state.
graph_update_user_phone_method
Pro · Destructive
Change the number on an existing phone authentication method — the ordinary fix when somebody changes handset or carrier.

Conditional Access

ToolWhat it does
graph_create_authentication_context
Pro · Write
Define an authentication context — one of the c1 to c25 labels an application can request to force step-up authentication on a specific action.
graph_create_authentication_strength_policy
Pro · Write
Define a custom authentication strength — a named set of method combinations that a Conditional Access policy can require.
graph_create_conditional_access_policy
Pro · Destructive
Create a Conditional Access policy.
graph_create_country_named_location
Pro · Write
Define a named location from a list of countries, for policies to refer to by name.
graph_create_ip_named_location
Pro · Write
Define a named location from IP ranges, for policies to refer to by name.
graph_delete_authentication_context
Pro · Destructive
Delete an authentication context.
graph_delete_authentication_strength_policy
Pro · Destructive
Delete a custom authentication strength policy.
graph_delete_conditional_access_policy
Pro · Destructive
Delete a Conditional Access policy permanently.
graph_delete_named_location
Pro · Destructive
Delete a named location.
graph_get_authentication_strength_policy
Free · Read-only
Get one authentication strength policy with its allowedCombinations — the exact method combinations that satisfy it.
graph_get_conditional_access_policy
Free · Read-only
Get one Conditional Access policy in full.
graph_get_named_location
Free · Read-only
Get one named location with its full definition.
graph_list_authentication_contexts
Free · Read-only
List the authentication context class references — the c1 to c25 labels that let an application ask for step-up authentication on a specific action rather than at sign-in.
graph_list_authentication_strength_policies
Free · Read-only
List the authentication strength policies — the named combinations of methods a Conditional Access policy can demand, such as Microsoft's built-in phishing-resistant MFA.
graph_list_conditional_access_policies
Free · Read-only
List every Conditional Access policy in the tenant with its conditions and grant controls.
graph_list_named_locations
Free · Read-only
List the named locations defined in the tenant — the IP ranges and countries that Conditional Access policies refer to by name.
graph_set_conditional_access_policy_state
Pro · Destructive
Turn a Conditional Access policy on, off, or into report-only mode.
graph_update_conditional_access_policy
Pro · Destructive
Update a Conditional Access policy's conditions or controls.
graph_update_named_location
Pro · Destructive
Update a named location's ranges, countries or trusted flag.

Administrative Units

ToolWhat it does
graph_add_administrative_unit_member
Pro · Write
Add a user, group or device to an administrative unit.
graph_add_administrative_unit_scoped_role
Pro · Destructive
Grant somebody an administrative role limited to this unit's members.
graph_create_administrative_unit
Pro · Write
Create an administrative unit.
graph_delete_administrative_unit
Pro · Destructive
Delete an administrative unit.
graph_get_administrative_unit
Free · Read-only
Get one administrative unit, including its membership rule if it has one and its visibility.
graph_list_administrative_unit_members
Free · Read-only
List the users, groups and devices inside an administrative unit.
graph_list_administrative_unit_scoped_role_members
Free · Read-only
List who holds an administrative role SCOPED to this unit — the people who can administer its members and nobody else.
graph_list_administrative_units
Free · Read-only
List the administrative units in a directory — the containers that let administrative power be scoped to part of the tenant rather than all of it.
graph_remove_administrative_unit_member
Pro · Destructive
Remove a user, group or device from an administrative unit.
graph_remove_administrative_unit_scoped_role
Pro · Destructive
Revoke somebody's administrative role over this unit.
graph_update_administrative_unit
Pro · Write
Update an administrative unit's name, description or visibility.
graph_update_administrative_unit_membership_rule
Pro · Destructive
Change the membership rule of a dynamic administrative unit.

Devices

ToolWhat it does
graph_add_device_registered_owner
Pro · Destructive
Register a user as an OWNER of a device.
graph_add_device_registered_user
Pro · Write
Register a user on a device — the record that this person uses this machine.
graph_delete_device
Pro · Destructive
Delete a device object from the directory.
graph_get_device
Free · Read-only
Get one device object in full — operating system and version, join and trust type, management authority, compliance flag and when it last signed in.
graph_list_device_memberships
Free · Read-only
List the groups and administrative units a device belongs to DIRECTLY.
graph_list_device_registered_owners
Free · Read-only
List the registered OWNERS of a device — normally the person who joined it to the directory.
graph_list_device_registered_users
Free · Read-only
List the users registered on a device — everyone who has signed in and established a device registration, which on a shared machine is a longer list than anyone expects.
graph_list_device_transitive_memberships
Free · Read-only
List every group and administrative unit a device belongs to, INCLUDING through nesting.
graph_list_devices
Free · Read-only
List the devices registered in a directory.
graph_remove_device_registered_owner
Pro · Destructive
Remove a user's OWNER registration on a device — the inverse of adding one, and destructive because it withdraws the local administrator rights an Entra-joined Windows machine grants its registered owner.
graph_remove_device_registered_user
Pro · Destructive
Remove a user's registration on a device.
graph_set_device_account_enabled
Pro · Destructive
Enable or disable a device's directory account.
graph_update_device
Pro · Write
Update a device object's descriptive properties — its display name, operating system and version.

Intune Devices

ToolWhat it does
graph_bypass_activation_lock
Pro · Destructive
Remove Apple's Activation Lock from a supervised device so it can be set up under a different Apple Account.
graph_clean_windows_device
Pro · Destructive
Reset a Windows device to its factory settings, the 'Autopilot Reset / fresh start' action.
graph_create_device_category
Pro · Write
Create an Intune device category.
graph_delete_device_category
Pro · Destructive
Delete an Intune device category.
graph_delete_managed_device
Pro · Destructive
Delete a device's RECORD from Intune.
graph_delete_user_from_shared_apple_device
Pro · Destructive
Remove one named user's account and cached data from a shared iPad.
graph_disable_managed_device_lost_mode
Pro · Destructive
Turn off Lost Mode on a supervised Apple device, returning it to ordinary use and ending the location tracking that Lost Mode enables.
graph_get_detected_app
Free · Read-only
Get one detected application — its display name, version, publisher, size and the number of devices reporting it.
graph_get_device_category
Free · Read-only
Get one Intune device category by id — its display name and description.
graph_get_managed_device
Free · Read-only
Get one Intune-managed device in full — hardware, operating system, storage, compliance and encryption state, enrolment details and the results of any remote actions already sent to it (deviceActionResults).
graph_get_managed_device_category
Free · Read-only
Get the device category assigned to one Intune-managed device.
graph_get_managed_device_protection_state
Free · Read-only
Get the Microsoft Defender protection state of a Windows device — real-time protection status, network inspection, signature version and age, malware protection enablement, last quick and full scan times, and whether a reboot is required to finish remediation.
graph_list_detected_app_devices
Free · Read-only
List the managed devices reporting a particular detected application.
graph_list_detected_apps
Free · Read-only
List the applications Intune has DETECTED across the enrolled fleet, with a device count for each.
graph_list_device_categories
Free · Read-only
List the Intune device categories defined in a tenant.
graph_list_managed_device_log_collections
Free · Read-only
List the diagnostic log collection requests raised against an Intune-managed device, with each request's status, size, the time it was requested and when it expires.
graph_list_managed_device_users
Free · Read-only
List the primary users associated with an Intune-managed device.
graph_list_managed_devices
Free · Read-only
List the devices enrolled in Intune.
graph_locate_managed_device
Pro · Write
Ask a supervised iOS/iPadOS or macOS device to report its location.
graph_logout_shared_apple_device_user
Pro · Destructive
Sign out whoever is currently signed in on a shared iPad.
graph_reboot_managed_device
Pro · Destructive
Restart a device now.
graph_recover_managed_device_passcode
Pro · Destructive
Ask a supervised device to surrender its current passcode to Intune.
graph_remote_lock_managed_device
Pro · Destructive
Lock a device remotely so it requires its passcode to be used again.
graph_request_remote_assistance
Pro · Write
Request a remote-assistance session for a device.
graph_reset_managed_device_passcode
Pro · Destructive
Remove or reset the passcode on a device.
graph_retire_managed_device
Pro · Destructive
Unenrol a device from Intune, removing company data, policies, certificates, Wi-Fi and VPN profiles and company applications while leaving the person's own data in place.
graph_shut_down_managed_device
Pro · Destructive
Power a device off immediately.
graph_sync_managed_device
Pro · Write
Ask a device to check in with Intune immediately rather than waiting for its scheduled cycle.
graph_update_device_category
Pro · Write
Update an Intune device category's name or description.
graph_update_managed_device
Pro · Write
Update the two properties Intune lets an administrator write on a managed device: managedDeviceName, the friendly name shown throughout the console, and notes.
graph_windows_defender_scan
Pro · Write
Start a Microsoft Defender scan on a Windows device.
graph_windows_defender_update_signatures
Pro · Write
Tell a Windows device to update its Microsoft Defender malware signatures now.
graph_wipe_managed_device
Pro · Destructive
FACTORY-RESET a device.

Intune Configuration

ToolWhat it does
graph_assign_device_compliance_policy
Pro · Destructive
Set which groups a compliance policy applies to.
graph_assign_device_configuration
Pro · Destructive
Set which groups a configuration profile applies to.
graph_create_device_compliance_policy
Pro · Write
Create an Intune compliance policy.
graph_create_device_configuration
Pro · Write
Create an Intune configuration profile.
graph_delete_device_compliance_policy
Pro · Destructive
Delete an Intune compliance policy.
graph_delete_device_configuration
Pro · Destructive
Delete an Intune configuration profile.
graph_get_device_compliance_device_overview
Free · Read-only
Get the device-level summary for a compliance policy — compliant, non-compliant, error, conflict, not-applicable and pending counts in one object.
graph_get_device_compliance_policy
Free · Read-only
Get one Intune compliance policy in full, with every rule it evaluates.
graph_get_device_compliance_user_overview
Free · Read-only
Get the user-level summary for a compliance policy — the same verdict counts aggregated by person rather than by machine.
graph_get_device_configuration
Free · Read-only
Get one Intune configuration profile in full, including every setting it carries.
graph_get_device_configuration_device_overview
Free · Read-only
Get the device-level rollout summary for a configuration profile — the counts of succeeded, error, conflict, not-applicable and pending devices in one small object.
graph_get_device_configuration_user_overview
Free · Read-only
Get the user-level rollout summary for a configuration profile — succeeded, error, conflict, not-applicable and pending counted by PERSON rather than by machine.
graph_get_oma_setting_secret
Pro · Destructive
Return the PLAIN-TEXT SECRET behind an encrypted OMA-URI setting in a Windows custom configuration profile — typically a VPN pre-shared key, a Wi-Fi passphrase or a certificate password.
graph_list_device_compliance_device_statuses
Free · Read-only
List each targeted device's verdict against a compliance policy, with the device name and when it last reported.
graph_list_device_compliance_policies
Free · Read-only
List the Intune device compliance policies in a tenant — the policies that MEASURE whether a device meets the rules, as opposed to configuration profiles, which set them.
graph_list_device_compliance_policy_assignments
Free · Read-only
List the groups a compliance policy is assigned to, including exclusions.
graph_list_device_compliance_scheduled_actions
Free · Read-only
List the scheduled actions attached to a compliance policy — what Intune does when a device fails, and how long it waits first.
graph_list_device_compliance_user_statuses
Free · Read-only
List each targeted user's aggregated verdict against a compliance policy.
graph_list_device_configuration_assignments
Free · Read-only
List the groups a configuration profile is assigned to, including whether each assignment INCLUDES or EXCLUDES that group.
graph_list_device_configuration_device_statuses
Free · Read-only
List how a configuration profile landed on each targeted DEVICE — succeeded, pending, error or conflict, with the device name and the time it last reported.
graph_list_device_configuration_user_statuses
Free · Read-only
List how a configuration profile landed for each targeted USER, aggregated across all of that person's devices.
graph_list_device_configurations
Free · Read-only
List the Intune device configuration profiles in a tenant — the profiles that SET things on devices, as opposed to compliance policies, which measure them.
graph_update_device_compliance_policy
Pro · Write
Update an Intune compliance policy.
graph_update_device_configuration
Pro · Write
Update an Intune configuration profile.

Identity Protection

ToolWhat it does
graph_confirm_users_compromised
Pro · Write
Tell Entra ID Protection that these accounts really were compromised, setting each to confirmedCompromised at high risk.
graph_dismiss_user_risk
Pro · Write
Dismiss the risk on these accounts, setting each to dismissed at none.
graph_get_risk_detection
Free · Read-only
Get one risk detection event in full — the detection type and its source, the IP address and resolved location, the client application, and the sign-in or user it was raised against.
graph_get_risky_user
Free · Read-only
Get one account's current risk verdict — level, state, detail and when it was last updated.
graph_list_risk_detections
Free · Read-only
List individual risk detection events — one row per thing Microsoft noticed, with the detection type, the IP address, the location and the activity it was attached to.
graph_list_risky_user_history
Free · Read-only
List how one account's risk state changed over time — every transition, what caused it, and the activity behind it.
graph_list_risky_users
Free · Read-only
List the accounts Entra ID Protection currently considers at risk.

Audit Logs

ToolWhat it does
graph_get_directory_audit
Free · Read-only
Get one directory audit event in full — the initiator, the category and result, and the targetResources array with the OLD and NEW values of every property that changed.
graph_get_sign_in
Free · Read-only
Get one sign-in event in full — the account and application, the client and device, the resolved location, the authentication methods that were satisfied, and every Conditional Access policy that was evaluated with the decision each reached.
graph_list_directory_audits
Free · Read-only
List directory audit events — every administrative change made in the tenant, with who made it, what it targeted and whether it succeeded.
graph_list_provisioning_logs
Free · Read-only
List provisioning events — what Entra's provisioning service synchronised into or out of a connected application, per object, with the outcome and the reason for it.
graph_list_sign_ins
Free · Read-only
List sign-in events — who signed in, when, from which IP address and location, on what device, to which application, and whether it succeeded.

Directory Objects

ToolWhat it does
graph_check_member_objects
Free · Read-only
Given a directory object and a list of group, role or administrative-unit ids, return the SUBSET it actually belongs to — transitively.
graph_create_invitation
Pro · Destructive
Invite an external person into the directory as a B2B guest.
graph_get_available_extension_properties
Free · Read-only
List the directory extension properties defined in this tenant — the custom fields an organization or a synchronisation tool has added to users, groups, devices or applications.
graph_get_directory_object
Free · Read-only
Get any directory object by its id without knowing what type it is.
graph_get_directory_objects_by_ids
Free · Read-only
Resolve many object ids to their directory objects in ONE call.
graph_get_member_groups
Free · Read-only
Return the ids of every GROUP a directory object belongs to, including through nesting.
graph_get_member_objects
Free · Read-only
Return the ids of every group, DIRECTORY ROLE and administrative unit a directory object belongs to, including through nesting.

Security

ToolWhat it does
graph_get_secure_score
Free · Read-only
Get one Secure Score snapshot in full, including controlScores — the per-control detail saying what each control contributed on that day and why.
graph_get_secure_score_control_profile
Free · Read-only
Get one Secure Score control definition in full — its title and category, the maximum score it can contribute, the threats it addresses, its user impact and implementation cost, and the remediation text.
graph_get_security_alert
Free · Read-only
Get one Defender XDR alert in full — the detection and its source, the incident it belongs to, and the evidence array naming the devices, accounts, files, processes and URLs involved.
graph_get_security_incident
Free · Read-only
Get one Defender XDR incident — its severity, status, assigned owner, classification and determination, plus the tags and comments analysts have added.
graph_list_secure_score_control_profiles
Free · Read-only
List the Secure Score control definitions — what each control is, which service it belongs to, what it is worth, the user impact of turning it on and the remediation steps.
graph_list_secure_scores
Free · Read-only
List Microsoft Secure Score snapshots — one per day, each with the tenant's score out of the maximum and the per-control breakdown behind it.
graph_list_security_alerts
Free · Read-only
List Defender XDR alerts — individual detections from Defender for Endpoint, Office 365, Identity and Cloud Apps.
graph_list_security_incident_alerts
Free · Read-only
List the alerts Defender correlated into one incident — the evidence behind the story.
graph_list_security_incidents
Free · Read-only
List Defender XDR incidents — correlated groups of alerts, which is the right unit to triage from.
graph_run_hunting_query
Free · Read-only
Run a Kusto Query Language (KQL) query against Microsoft Defender's advanced hunting schema — raw event data across devices, email, identities and cloud apps, going back 30 days by default.
graph_update_secure_score_control_profile
Pro · Write
Record a tenant's own position on a Secure Score control — Default, Ignored, ThirdParty or Reviewed — with an optional note.
graph_update_security_alert
Pro · Write
Update an alert's status, classification, determination or assigned owner.
graph_update_security_incident
Pro · Write
Update an incident's status, classification, determination, assigned owner or display name.

Usage Reports

ToolWhat it does
graph_report_email_activity_counts
Free · Read-only
Tenant-wide email totals per day — messages sent, received and read across the whole organization.
graph_report_email_activity_user_detail
Free · Read-only
Per-user email activity — send, receive and read counts, and each mailbox's last activity date.
graph_report_email_app_usage_user_detail
Free · Read-only
Which email CLIENTS each user actually connects with — Outlook desktop, Outlook mobile, Outlook Web, IMAP, POP, SMTP.
graph_report_m365_app_platform_user_counts
Free · Read-only
Daily counts of users active on each PLATFORM — Windows, Mac, mobile and web.
graph_report_m365_app_user_counts
Free · Read-only
Daily counts of users active in each Microsoft 365 app across the tenant.
graph_report_m365_app_user_detail
Free · Read-only
Per-user Microsoft 365 Apps usage broken down by application AND platform — Word, Excel, Outlook, Teams and the rest, on Windows, Mac, mobile and web.
graph_report_mailbox_usage_detail
Free · Read-only
Per-mailbox storage — bytes used against the quota, item count, and quota status.
graph_report_mailbox_usage_storage
Free · Read-only
Total mailbox storage consumed across the tenant, per day.
graph_report_office365_activation_counts
Free · Read-only
Office activation totals per product and platform across the tenant — how many activations exist for each, rather than who holds them.
graph_report_office365_activations_user_detail
Free · Read-only
Per-user desktop Office activations — which platforms each person has activated on (Windows, Mac, iOS, Android) and whether it was a shared computer.
graph_report_office365_active_user_counts
Free · Read-only
Daily counts of active users per service across the tenant.
graph_report_office365_active_user_detail
Free · Read-only
The single most useful report here: one row per user, with which products they are LICENSED for and their last activity date in EACH — Exchange, OneDrive, SharePoint, Teams, Yammer.
graph_report_office365_services_user_counts
Free · Read-only
Enabled versus ACTIVE user counts per service — how many people are licensed for each product against how many actually used it.
graph_report_onedrive_activity_user_detail
Free · Read-only
Per-user OneDrive activity — files viewed or edited, synced, shared internally and shared EXTERNALLY.
graph_report_onedrive_usage_account_detail
Free · Read-only
Per-account OneDrive storage — files, active files, bytes used against bytes allocated, and last activity.
graph_report_sharepoint_activity_user_detail
Free · Read-only
Per-user SharePoint activity — files viewed or edited, synced, shared internally and externally, and pages visited.
graph_report_sharepoint_site_usage_detail
Free · Read-only
Per-SITE SharePoint usage — storage used and allocated, file and page counts, visitors, and last activity.
graph_report_teams_device_usage_user_detail
Free · Read-only
Which DEVICES each person uses Teams from — Windows, Mac, iOS, Android, web and Linux.
graph_report_teams_user_activity_counts
Free · Read-only
Tenant-wide Teams totals per day — messages, meetings and calls across the organization.
graph_report_teams_user_activity_user_detail
Free · Read-only
Per-user Teams activity — channel messages, chat messages, meetings attended and organised, and calls.
graph_report_yammer_activity_user_detail
Free · Read-only
Per-user Viva Engage (formerly Yammer) activity — messages posted, read and liked, with last activity date.

Mail

ToolWhat it does
graph_copy_message
Pro · Write
Copy a message into another folder, leaving the original where it is.
graph_create_draft_message
Pro · Write
Create a message in the Drafts folder without sending it.
graph_create_forward_draft
Pro · Write
Create a forward DRAFT of a message, with its attachments, without sending it.
graph_create_mail_folder
Pro · Write
Create a mail folder, either at the top level or beneath an existing folder.
graph_create_message_rule
Pro · Destructive
Create a rule on the signed-in user's Inbox.
graph_create_reply_draft
Pro · Write
Create a reply DRAFT to a message — correctly threaded and addressed, quoting the original — without sending it.
graph_delete_mail_folder
Pro · Destructive
Delete a mail folder AND EVERYTHING IN IT, including its subfolders and every message they hold.
graph_delete_message
Pro · Destructive
Delete a message.
graph_delete_message_rule
Pro · Destructive
Delete an inbox rule permanently — there is no undo and no copy kept.
graph_download_message_attachment
Free · Read-only
Download an attachment's raw bytes and return a short-lived read-only download link, together with the content type, filename and size.
graph_forward_message
Pro · Destructive
Forward a message, with its attachments, to new recipients and send it immediately.
graph_get_mail_folder
Free · Read-only
Get one mail folder by id or by well-known name.
graph_get_mailbox_settings
Free · Read-only
Get the signed-in user's mailbox settings — automatic replies (out-of-office) and their schedule, time zone, working hours, language, date and time format, and how delegated meeting messages are handled.
graph_get_message
Free · Read-only
Get one message in full, including its body and internet headers.
graph_get_message_attachment
Free · Read-only
Get one attachment as JSON.
graph_get_message_rule
Free · Read-only
Get one inbox rule in full.
graph_list_child_mail_folders
Free · Read-only
List the folders directly beneath one mail folder.
graph_list_mail_categories
Free · Read-only
List the signed-in user's master list of Outlook categories — the coloured labels shared across messages, events, contacts and tasks.
graph_list_mail_folder_messages
Free · Read-only
List the messages inside one mail folder, by folder id or well-known name.
graph_list_mail_folders
Free · Read-only
List the top-level mail folders in the signed-in user's mailbox, with unread and total item counts.
graph_list_message_attachments
Free · Read-only
List a message's attachments as METADATA — name, content type and size — without pulling any content down.
graph_list_message_rules
Free · Read-only
List every rule on the signed-in user's INBOX, with its conditions, actions and exceptions.
graph_list_messages
Free · Read-only
List messages in the signed-in user's mailbox, newest first unless you order them otherwise.
graph_move_message
Pro · Write
Move a message to another folder, by folder id or well-known name such as "archive", "junkemail" or "deleteditems".
graph_reply_all_to_message
Pro · Destructive
Reply to EVERYONE on a message — sender, To and CC — and send it immediately.
graph_reply_to_message
Pro · Destructive
Reply to a message's SENDER only and send it immediately.
graph_search_messages
Free · Read-only
Free-text search across the signed-in user's mailbox, including message bodies and the text of supported attachment types.
graph_send_draft_message
Pro · Destructive
Send a draft that already exists in the mailbox.
graph_send_mail
Pro · Destructive
Send a message immediately AS THE SIGNED-IN USER, from their real address.
graph_set_automatic_replies
Pro · Write
Turn the signed-in user's out-of-office automatic reply on, off, or on for a scheduled window.
graph_update_mail_folder
Pro · Write
Rename a mail folder.
graph_update_message
Pro · Write
Update a message's mutable properties — read state, importance and categories.
graph_update_message_rule
Pro · Destructive
Change an existing inbox rule.

Files

ToolWhat it does
graph_copy_drive_item
Pro · Write
Copy a file or folder, optionally into a different drive and optionally under a new name.
graph_create_folder
Pro · Write
Create a folder, in the drive's root or inside an existing folder.
graph_create_sharing_link
Pro · Destructive
Create a sharing link for a file or folder and RETURN THE URL.
graph_delete_drive_item
Pro · Destructive
Delete a file or folder.
graph_delete_item_permission
Pro · Destructive
Remove a permission from a file or folder — the remediation for an oversharing finding, and the way an anonymous link is killed.
graph_download_drive_item
Free · Read-only
Download a file's content and return a short-lived read-only download link, with its content type, filename and size.
graph_get_drive
Free · Read-only
Get one drive, including its quota — total, used, remaining and the deleted bytes still held in the recycle bin.
graph_get_drive_item
Free · Read-only
Get one file or folder by id — size, timestamps, the person who last changed it, and the webUrl that opens it in a browser for someone who already has access.
graph_get_drive_item_by_path
Free · Read-only
Get a file or folder by its path within the drive, for example "Documents/Invoices/2026-Q3.xlsx".
graph_invite_to_drive_item
Pro · Destructive
Grant named people access to a file or folder, optionally emailing them an invitation.
graph_list_drive_item_versions
Free · Read-only
List the stored versions of a file, newest first, with who saved each one and how large it was.
graph_list_drive_items
Free · Read-only
List the files and folders directly inside one folder, or inside the drive's root when no folder is named.
graph_list_drives
Free · Read-only
List drives — the signed-in user's own OneDrive by default, or every document library belonging to a SharePoint site or a Microsoft 365 group when you name one.
graph_list_item_permissions
Free · Read-only
List everyone and everything that can reach a file or folder — people granted access directly, permissions inherited from a parent folder, and every sharing link that exists on it.
graph_list_recent_files
Free · Read-only
List the files the signed-in user most recently viewed or edited, across every drive they can reach rather than one at a time.
graph_list_shared_with_me
Free · Read-only
List files and folders other people have shared with the signed-in user.
graph_move_drive_item
Pro · Write
Move a file or folder to a different folder in the SAME drive, optionally renaming it on the way.
graph_rename_drive_item
Pro · Write
Rename a file or folder.
graph_restore_drive_item_version
Pro · Write
Restore a previous version of a file, making it the current content.
graph_search_drive_items
Free · Read-only
Search a drive for files and folders matching a term, across the whole hierarchy rather than one folder.
graph_update_item_permission
Pro · Destructive
Change an existing permission's roles or expiry — turning read access into write, or putting an expiry on a link that has none.

Calendar

ToolWhat it does
graph_cancel_event
Pro · Destructive
Cancel a meeting the signed-in user ORGANISED, sending a cancellation notice to every attendee.
graph_create_calendar
Pro · Write
Create an additional calendar for the signed-in user.
graph_create_calendar_permission
Pro · Destructive
Share a calendar with somebody, choosing how much they can see.
graph_create_event
Pro · Destructive
Create an event.
graph_delete_calendar
Pro · Destructive
Delete a calendar AND EVERY EVENT IN IT.
graph_delete_calendar_permission
Pro · Destructive
Remove somebody's access to a calendar — the remediation when an audit finds a share that should not exist.
graph_delete_event
Pro · Destructive
Delete an event from the signed-in user's calendar.
graph_download_event_attachment
Free · Read-only
Download an event attachment's raw bytes and return a short-lived read-only download link, with its content type, filename and size.
graph_forward_event
Pro · Destructive
Forward a meeting invitation to additional people, who receive a real invitation and appear to the organiser as attendees.
graph_get_calendar
Free · Read-only
Get one calendar, or the signed-in user's default calendar when no id is given.
graph_get_event
Free · Read-only
Get one event in full — attendees and each person's response status, the organiser, location, body, online-meeting join details and, for a series, its recurrence rule.
graph_get_schedule
Free · Read-only
Get free/busy availability for one or more people, distribution lists, or bookable resources such as meeting rooms, over a time window.
graph_list_calendar_permissions
Free · Read-only
List who a calendar is shared with and how much each of them can see.
graph_list_calendar_view
Free · Read-only
List the events occurring between two times, with recurring series EXPANDED into their individual occurrences.
graph_list_calendars
Free · Read-only
List the signed-in user's calendars — their default one plus any extra calendars they created or had shared with them.
graph_list_event_attachments
Free · Read-only
List an event's attachments as metadata — name, content type and size — without pulling any content down.
graph_list_event_instances
Free · Read-only
List the individual occurrences of ONE recurring series within a date range, including any that were moved or cancelled separately from the rest.
graph_list_events
Free · Read-only
List events as they are STORED, which means a recurring series comes back as a single master entry carrying its recurrence rule rather than as its occurrences.
graph_respond_to_event
Pro · Destructive
Answer a meeting invitation as the signed-in user — accept, decline, or accept tentatively.
graph_update_calendar
Pro · Write
Rename a calendar or change the colour Outlook shows it in.
graph_update_event
Pro · Destructive
Change an event.

Contacts

ToolWhat it does
graph_create_contact
Pro · Write
Add a contact to the signed-in user's personal address book, optionally inside a folder.
graph_delete_contact
Pro · Destructive
Delete a contact from the signed-in user's personal address book.
graph_get_contact
Free · Read-only
Get one personal contact in full — every email address and phone number on the record, the postal addresses, job title and company, and any personal notes.
graph_get_org_contact
Free · Read-only
Get one organizational contact from the directory.
graph_list_contact_folder_contacts
Free · Read-only
List the contacts inside one contact folder.
graph_list_contact_folders
Free · Read-only
List the folders the signed-in user files contacts into.
graph_list_contacts
Free · Read-only
List the signed-in user's personal Outlook contacts — their own private address book, not the organisation's shared directory.
graph_list_org_contacts
Free · Read-only
List the tenant's ORGANIZATIONAL contacts — the shared directory entries everyone in the organisation sees in the global address list, typically outside accountants, suppliers and contractors who have no mailbox of their own.
graph_update_contact
Pro · Write
Change a personal contact.

SharePoint

ToolWhat it does
graph_create_list
Pro · Write
Create a new list in a SharePoint site.
graph_create_list_column
Pro · Write
Add a column to a SharePoint list.
graph_create_list_item
Pro · Write
Add a row to a SharePoint list.
graph_delete_list
Pro · Destructive
Delete a SharePoint list AND EVERY ITEM IN IT.
graph_delete_list_column
Pro · Destructive
Remove a column from a SharePoint list.
graph_delete_list_item
Pro · Destructive
Delete one row from a SharePoint list.
graph_get_list
Free · Read-only
Get one SharePoint list — its display name, template type, item count hints and whether it is hidden.
graph_get_list_item
Free · Read-only
Get one row of a SharePoint list with all its column values.
graph_get_root_site
Free · Read-only
Get the organisation's root SharePoint site — the tenant's default site collection, the one at the bare https://{tenant}.sharepoint.com address.
graph_get_site
Free · Read-only
Get one SharePoint site by its id.
graph_get_site_by_path
Free · Read-only
Resolve a SharePoint site from the address a person would paste from their browser, splitting it into its two halves.
graph_list_content_type_columns
Free · Read-only
List the columns a site content type contributes.
graph_list_list_columns
Free · Read-only
List the columns defined on one SharePoint list — their internal names, types, and whether each is required or read-only.
graph_list_list_item_versions
Free · Read-only
List the previous versions of one list item, each with who changed it and when.
graph_list_list_items
Free · Read-only
List the rows in a SharePoint list, WITH their column values.
graph_list_site_columns
Free · Read-only
List the SITE columns — reusable column definitions available to every list in the site, as opposed to the per-list columns graph_list_list_columns returns.
graph_list_site_content_types
Free · Read-only
List the content types defined on a SharePoint site.
graph_list_site_lists
Free · Read-only
List the lists in a SharePoint site.
graph_list_sites
Free · Read-only
List the SharePoint sites in the organisation.
graph_list_subsites
Free · Read-only
List the subsites directly under one SharePoint site.
graph_search_sites
Free · Read-only
Find SharePoint sites by keyword — the fastest way to turn a site NAME a person used into the site id every other tool here needs.
graph_update_list
Pro · Write
Rename a list or change its description.
graph_update_list_item
Pro · Write
Change column values on one row.

Teams

ToolWhat it does
graph_add_channel_member
Pro · Destructive
Add somebody to a PRIVATE or SHARED channel, granting them its whole history and its own files.
graph_add_team_member
Pro · Destructive
Add somebody to a team.
graph_archive_channel
Pro · Destructive
Archive a channel, making it READ-ONLY for everyone: nobody can post, reply, react or change its settings until it is unarchived.
graph_archive_team
Pro · Destructive
Archive a team, making it READ-ONLY FOR EVERY MEMBER at once — nobody can post, reply or change anything until it is unarchived.
graph_create_channel
Pro · Write
Add a channel to a team.
graph_create_team
Pro · Write
Create a new team.
graph_delete_channel
Pro · Destructive
Delete a channel AND ITS ENTIRE CONVERSATION HISTORY.
graph_get_channel
Free · Read-only
Get one channel — its description, its membershipType (standard, private or shared) and its web URL.
graph_get_channel_files_folder
Free · Read-only
Get the SharePoint folder holding a channel's files.
graph_get_channel_message
Free · Read-only
Get one channel post in full — its body, who wrote it, when, whether it has been edited or deleted, and any attachments or mentions.
graph_get_team
Free · Read-only
Get one team with its settings — who may create channels, whether guests can be added, whether members can delete messages, and whether the team is archived.
graph_get_team_member
Free · Read-only
Get one team membership.
graph_list_all_channels
Free · Read-only
List EVERY channel in a team including private and shared ones, each with its membershipType.
graph_list_channel_members
Free · Read-only
List the members of a PRIVATE or SHARED channel — the people who can see it beyond the team's own membership.
graph_list_channel_messages
Free · Read-only
List the top-level posts in a channel, newest first.
graph_list_channel_tabs
Free · Read-only
List the tabs pinned across the top of a channel — the wikis, Planner boards, websites and documents a team has attached to it.
graph_list_channels
Free · Read-only
List a team's STANDARD channels — the ones every member sees.
graph_list_joined_teams
Free · Read-only
List the teams the SIGNED-IN user belongs to.
graph_list_message_replies
Free · Read-only
List the replies to one channel post — the actual discussion, which the channel listing omits.
graph_list_team_installed_apps
Free · Read-only
List the Teams apps installed in a team.
graph_list_team_members
Free · Read-only
List a team's members.
graph_list_teams
Free · Read-only
List the teams in the organisation.
graph_remove_channel_member
Pro · Destructive
Remove somebody from a private or shared channel.
graph_remove_team_member
Pro · Destructive
Remove somebody from a team.
graph_reply_to_channel_message
Pro · Destructive
Reply to an existing channel post, in that post's thread.
graph_send_channel_message
Pro · Destructive
Post a message to a Teams channel.
graph_unarchive_channel
Pro · Write
Restore an archived channel, giving its members back the ability to post and edit.
graph_unarchive_team
Pro · Write
Restore an archived team to normal use.
graph_update_channel
Pro · Write
Rename a channel or change its description.
graph_update_team
Pro · Write
Change a team's name or description.
graph_update_team_member_role
Pro · Destructive
Promote a team member to owner, or demote an owner back to a member.

Chats & Presence

ToolWhat it does
graph_add_chat_member
Pro · Destructive
Add somebody to a group chat.
graph_get_chat
Free · Read-only
Get one chat — its type (oneOnOne, group or meeting), its topic if it has one, and when it was last updated.
graph_get_chat_message
Free · Read-only
Get one chat message in full — its body, sender, timestamps, attachments and mentions.
graph_get_presences
Free · Read-only
Get the Teams availability of up to 650 people in ONE call.
graph_get_user_presence
Free · Read-only
Get one person's Teams availability — Available, Busy, DoNotDisturb, Away or Offline, plus the activity behind it (InACall, InAMeeting, Presenting).
graph_list_chat_members
Free · Read-only
List who is in a chat.
graph_list_chat_messages
Free · Read-only
List the messages in one chat, newest first.
graph_list_chats
Free · Read-only
List the SIGNED-IN user's Teams chats — one-to-one, group and meeting conversations.
graph_list_pinned_chat_messages
Free · Read-only
List the messages pinned to the top of a chat.
graph_pin_chat_message
Pro · Write
Pin a message to the top of a chat so everyone in it sees it first.
graph_send_chat_message
Pro · Destructive
Send a message to an existing Teams chat.
graph_unpin_chat_message
Pro · Write
Remove a pin from a chat.

Intune Applications

ToolWhat it does
graph_assign_mobile_app
Pro · Destructive
Set which groups an app is deployed to.
graph_create_intune_role_assignment
Pro · Destructive
Grant an Intune role to one or more security groups.
graph_create_intune_role_definition
Pro · Write
Author a custom Intune administrator role.
graph_delete_intune_role_assignment
Pro · Destructive
Revoke an Intune role assignment.
graph_delete_intune_role_definition
Pro · Destructive
Delete a custom Intune role.
graph_get_intune_role_definition
Free · Read-only
Get one Intune role with its full permission list.
graph_get_managed_app_policy
Free · Read-only
Get one app protection or app configuration policy with all its settings.
graph_get_managed_app_registration
Free · Read-only
Get one app registration — which person, which app, which device, which platform version, and when it last checked in.
graph_get_mobile_app
Free · Read-only
Get one managed application in full.
graph_get_vpp_token
Pro · Destructive
Get one Apple Volume Purchase Program token, INCLUDING ITS VALUE — the same credential disclosure as graph_list_vpp_tokens, for a single token.
graph_list_applied_app_policies
Free · Read-only
List the policies ACTUALLY IN FORCE for one app registration — what is really protecting that person's app right now.
graph_list_intended_app_policies
Free · Read-only
List the policies that SHOULD apply to one app registration — what has been targeted at it, as opposed to what has actually taken effect.
graph_list_intune_role_assignments
Free · Read-only
List who holds one Intune role, and over which scope.
graph_list_intune_role_definitions
Free · Read-only
List Intune's own administrator roles — the built-in ones (Help Desk Operator, Application Manager, Read Only Operator) and any custom roles.
graph_list_managed_app_policies
Free · Read-only
List Intune's app protection and app configuration policies — the MAM rules that control copy-paste out of company apps, save-as to personal storage, and PIN requirements.
graph_list_managed_app_registrations
Free · Read-only
List the app-and-user pairings MAM knows about — each is one person using one managed app on one device, with the platform, app version and last sync time.
graph_list_managed_app_statuses
Free · Read-only
Get Intune's own summary reports on app protection — aggregate counts of users and apps by policy state.
graph_list_mobile_app_assignments
Free · Read-only
List which groups an app is deployed to and how — required (installed automatically), available (offered in Company Portal) or uninstall (actively removed).
graph_list_mobile_apps
Free · Read-only
List the applications Intune manages — store apps, line-of-business packages and web links across every platform.
graph_list_vpp_tokens
Pro · Destructive
List the Apple Volume Purchase Program tokens uploaded to Intune, INCLUDING EACH TOKEN'S VALUE.
graph_target_managed_app_policy
Pro · Destructive
Set which apps an app protection policy covers.
graph_update_intune_role_assignment
Pro · Destructive
Change an existing Intune role assignment's members or scope.
graph_update_intune_role_definition
Pro · Destructive
Change a custom Intune role's name, description or permissions.

Partner Center (CSP)

ToolWhat it does
graph_get_partner_customer
Free · Read-only
Get one CSP customer's account record — company profile, primary domain, relationship to the partner and the tenant id everything else keys on.
graph_get_partner_customer_usage_records
Free · Read-only
Get the current billing period's rated usage for a customer's Azure subscriptions — spend so far, per subscription, before the invoice exists.
graph_get_partner_invoice
Free · Read-only
Get one invoice's header — billing period, totals by currency, due date and the document links.
graph_get_partner_order
Free · Read-only
Get one CSP order by id, with its line items, quantities, offer ids and current status.
graph_get_partner_service_request
Free · Read-only
Get one Microsoft service request in full — its status, severity, product area and the support engineer's notes.
graph_get_partner_subscription
Free · Read-only
Get one CSP subscription in full, including its offer, quantity, commitment term, auto-renew setting and — for an add-on — the parent subscription it hangs off.
graph_get_partner_subscription_resource_usage_records
Free · Read-only
Break one Azure subscription's current-period spend down by resource.
graph_list_partner_customer_orders
Free · Read-only
List the orders placed for a CSP customer — what was bought, when, at what quantity and on which billing cycle.
graph_list_partner_customer_service_requests
Free · Read-only
List the Microsoft support tickets raised on a customer's behalf, with their status and severity.
graph_list_partner_customer_subscriptions
Free · Read-only
List everything a CSP customer is subscribed to — offer, quantity, billing cycle, term, status and renewal settings.
graph_list_partner_customers
Free · Read-only
List the customers in this partner's CSP account — everyone the partner bills, with their company name, domain and tenant id.
graph_list_partner_invoice_line_items
Free · Read-only
List an invoice's line items for one billing provider — the per-customer, per-subscription detail that actually explains a bill.
graph_list_partner_invoices
Free · Read-only
List the partner's own invoices from Microsoft — invoice id, billing period, currency, total and payment status.
graph_list_partner_subscriptions_by_order
Free · Read-only
List the subscriptions one order produced.
graph_search_partner_customers
Free · Read-only
Find CSP customers whose company name starts with a given string.

Raw Requests

ToolWhat it does
graph_raw_get
Free · Read-only
Send one GET to any Microsoft Graph path, on v1.0 or beta, and return the response exactly as Graph sent it.
graph_raw_request
Pro · Destructive
Send one POST, PUT, PATCH or DELETE to any Microsoft Graph path, on v1.0 or beta, and return the response exactly as Graph sent it.