azure-graph
Read a Microsoft Graph collection with the credentials of an Azure connect profile.
azure-graph [profile=VALUE] path=VALUE [beta=VALUE]
- profile=VALUE
- Optional. Azure connect profile name
- path=VALUE
- Required. Path under the API version, for example
/users?$filter=userType eq 'Guest' - beta=VALUE
- Optional. Call /beta instead of /v1.0. Some resources are still beta only.
Output Fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile_name | String | Profile | Connect profile the row came from. Remaining fields are those the resource returns. |
Examples
Verified domains and their password policy
azure-graph profile="prod" path="/domains"
Guest accounts
azure-graph profile="prod" path="/users?$filter=userType eq 'Guest'"
Conditional access policies
azure-graph profile="prod" path="/identity/conditionalAccess/policies"
Directory role holders, expanded in one call
azure-graph profile="prod" path="/directoryRoles?$expand=members"
Endpoint and permissions
- Calls
GET https://graph.microsoft.com/v1.0{path}, or/beta{path}withbeta=t.@odata.nextLinkpaging is followed automatically. - Requires an API permission on the app registration with admin consent granted -
Directory.Read.Allfor users and roles,Policy.Read.Allfor conditional access. This is separate from the subscription RBAC thatazure-resource-graphneeds: the two planes share one app registration but are authorised in different places. - The path is everything after the API version, starting with
/. OData options ($filter,$select,$expand,$top) work as documented by Microsoft Graph.