conditionalAccessClientApplications resource type

Namespace: microsoft.graph

Important

APIs under the /beta version in Microsoft Graph are subject to change. Use of these APIs in production applications is not supported. To determine whether an API is available in v1.0, use the Version selector.

Represents client applications (service principals and workload identities) included in and excluded from the policy scope.

Properties

Property Type Description
excludeServicePrincipals String collection Service principal IDs excluded from the policy scope.
includeServicePrincipals String collection Service principal IDs included in the policy scope, or ServicePrincipalsInMyTenant.
servicePrincipalFilter conditionalAccessFilter Filter that defines the dynamic-servicePrincipal-syntax rule to include/exclude service principals. A filter can use custom security attributes to include/exclude service principals.

Relationships

None.

JSON representation

The following is a JSON representation of the resource.

{
  "@odata.type": "#microsoft.graph.conditionalAccessClientApplications",
  "includeServicePrincipals": [
    "String"
  ],
  "excludeServicePrincipals": [
    "String"
  ],
  "servicePrincipalFilter": {"@odata.type": "microsoft.graph.conditionalAccessFilter"},
}