Microsoft Azure

Download 168
Last updated Sep 7, 2026

azure-graph

Read a Microsoft Graph collection with the credentials of an Azure connect profile.

azure-graph [profile=VALUE] path=VALUE [beta=VALUE]
profile=VALUE
Optional. Azure connect profile name
path=VALUE
Required. Path under the API version, for example /users?$filter=userType eq 'Guest'
beta=VALUE
Optional. Call /beta instead of /v1.0. Some resources are still beta only.

Output Fields

FieldTypeNameDescription
profile_nameStringProfileConnect profile the row came from. Remaining fields are those the resource returns.

Examples

Verified domains and their password policy

azure-graph profile="prod" path="/domains"

Guest accounts

azure-graph profile="prod" path="/users?$filter=userType eq 'Guest'"

Conditional access policies

azure-graph profile="prod" path="/identity/conditionalAccess/policies"

Directory role holders, expanded in one call

azure-graph profile="prod" path="/directoryRoles?$expand=members"

Endpoint and permissions

  • Calls GET https://graph.microsoft.com/v1.0{path}, or /beta{path} with beta=t. @odata.nextLink paging is followed automatically.
  • Requires an API permission on the app registration with admin consent granted - Directory.Read.All for users and roles, Policy.Read.All for conditional access. This is separate from the subscription RBAC that azure-resource-graph needs: the two planes share one app registration but are authorised in different places.
  • The path is everything after the API version, starting with /. OData options ($filter, $select, $expand, $top) work as documented by Microsoft Graph.