Update the properties of a user object.
To use this API to update an agentUser, specify an @odata.type property with a value of #microsoft.graph.agentUser in the request body.
Update the properties of a user object.
To use this API to update an agentUser, specify an @odata.type property with a value of #microsoft.graph.agentUser in the request body.
This example updates the specified user's display name.
Parameters
-AboutMe
A freeform text entry field for the user to describe themselves.
Requires $select to retrieve.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-AccountEnabled
true if the account is enabled; otherwise, false.
This property is required when a user is created.
Requires $select to retrieve.
Supports $filter (eq, ne, not, and in).
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Activities
The user's activities across devices.
Read-only.
Nullable.
To construct, see NOTES section for ACTIVITIES properties and create a hash table.
Sets the age group of the user.
Allowed values: null, Minor, NotAdult, and Adult.
For more information, see legal age group property definitions.
Requires $select to retrieve.
Supports $filter (eq, ne, not, and in).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-AgreementAcceptances
The user's terms of use acceptance statuses.
Read-only.
Nullable.
To construct, see NOTES section for AGREEMENTACCEPTANCES properties and create a hash table.
Represents the app roles a user is granted for an application.
Supports $expand.
To construct, see NOTES section for APPROLEASSIGNMENTS properties and create a hash table.
The licenses that are assigned to the user, including inherited (group-based) licenses.
This property doesn't differentiate between directly assigned and inherited licenses.
Use the licenseAssignmentStates property to identify the directly assigned and inherited licenses.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq, not, /$count eq 0, /$count ne 0).
To construct, see NOTES section for ASSIGNEDLICENSES properties and create a hash table.
The plans that are assigned to the user.
Read-only.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq and not).
To construct, see NOTES section for ASSIGNEDPLANS properties and create a hash table.
The birthday of the user.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014, is 2014-01-01T00:00:00Z.
Requires $select to retrieve.
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-BodyParameter
user
To construct, see NOTES section for BODYPARAMETER properties and create a hash table.
The telephone numbers for the user.
NOTE: Although it's a string collection, only one number can be set for this property.
Read-only for users synced from the on-premises directory.
Returned by default.
Supports $filter (eq, not, ge, le, startsWith).
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
Parameter properties
Type:
System.String[]
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Calendar
calendar
To construct, see NOTES section for CALENDAR properties and create a hash table.
The city where the user is located.
Maximum length is 128 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-CloudClipboard
cloudClipboardRoot
To construct, see NOTES section for CLOUDCLIPBOARD properties and create a hash table.
The name of the company that the user is associated with.
This property can be useful for describing the company that a guest comes from.
The maximum length is 64 characters.Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Confirm
Prompts you for confirmation before running the cmdlet.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Supports wildcards:
False
DontShow:
False
Aliases:
cf
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ConsentProvidedForMinor
Sets whether consent was obtained for minors.
Allowed values: null, Granted, Denied, and NotRequired.
For more information, see legal age group property definitions.
Requires $select to retrieve.
Supports $filter (eq, ne, not, and in).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ContactFolders
The user's contacts folders.
Read-only.
Nullable.
To construct, see NOTES section for CONTACTFOLDERS properties and create a hash table.
The country or region where the user is located; for example, US or UK.
Maximum length is 128 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-CreatedDateTime
The date and time the user was created, in ISO 8601 format and UTC.
The value can't be modified and is automatically populated when the entity is created.
Nullable.
For on-premises users, the value represents when they were first created in Microsoft Entra ID.
Property is null for some users created before June 2018 and on-premises users that were synced to Microsoft Entra ID before June 2018.
Read-only.
Requires $select to retrieve.
Supports $filter (eq, ne, not , ge, le, in).
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-CreatedObjects
Directory objects that the user created.
Read-only.
Nullable.
To construct, see NOTES section for CREATEDOBJECTS properties and create a hash table.
Indicates whether the user account was created through one of the following methods: As a regular school or work account (null).
As an external account (Invitation).
As a local account for an Azure Active Directory B2C tenant (LocalAccount).
Through self-service sign-up by an internal user using email verification (EmailVerified).
Through self-service sign-up by a guest signing up through a link that is part of a user flow (SelfServiceSignUp).
Read-only.Requires $select to retrieve.
Supports $filter (eq, ne, not, in).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-CustomSecurityAttributes
customSecurityAttributeValue
Parameter properties
Type:
System.Collections.Hashtable
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-DataSecurityAndGovernance
userDataSecurityAndGovernance
To construct, see NOTES section for DATASECURITYANDGOVERNANCE properties and create a hash table.
Date and time when this object was deleted.
Always null when the object hasn't been deleted.
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Department
The name of the department in which the user works.
Maximum length is 64 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not , ge, le, in, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-DeviceEnrollmentLimit
The limit on the maximum number of devices that the user is permitted to enroll.
Allowed values are 5 or 1000.
Parameter properties
Type:
System.Int32
Default value:
0
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-DeviceManagementTroubleshootingEvents
The list of troubleshooting events for this user.
To construct, see NOTES section for DEVICEMANAGEMENTTROUBLESHOOTINGEVENTS properties and create a hash table.
The users and contacts that report to the user.
(The users and contacts that have their manager property set to this user.) Read-only.
Nullable.
Supports $expand.
To construct, see NOTES section for DIRECTREPORTS properties and create a hash table.
The name displayed in the address book for the user.
This value is usually the combination of the user's first name, middle initial, and family name.
This property is required when a user is created and it can't be cleared during updates.
Maximum length is 256 characters.
Returned by default.
Supports $filter (eq, ne, not , ge, le, in, startsWith, and eq on null values), $orderby, and $search.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Drive
drive
To construct, see NOTES section for DRIVE properties and create a hash table.
The date and time when the user was hired or will start work in a future hire.
Requires $select to retrieve.
Supports $filter (eq, ne, not , ge, le, in).
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-EmployeeId
The employee identifier assigned to the user by the organization.
The maximum length is 16 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not , ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-EmployeeLeaveDateTime
The date and time when the user left or will leave the organization.
To read this property, the calling app must be assigned the User-LifeCycleInfo.Read.All permission.
To write this property, the calling app must be assigned the User.Read.All and User-LifeCycleInfo.ReadWrite.All permissions.
To read this property in delegated scenarios, the admin needs at least one of the following Microsoft Entra roles: Lifecycle Workflows Administrator (least privilege), Global Reader.
To write this property in delegated scenarios, the admin needs the Global Administrator role.
Supports $filter (eq, ne, not , ge, le, in).
For more information, see Configure the employeeLeaveDateTime property for a user.
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-EmployeeOrgData
employeeOrgData
To construct, see NOTES section for EMPLOYEEORGDATA properties and create a hash table.
Captures enterprise worker type.
For example, Employee, Contractor, Consultant, or Vendor.
Requires $select to retrieve.
Supports $filter (eq, ne, not , ge, le, in, startsWith).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Events
The user's events.
Default is to show Events under the Default Calendar.
Read-only.
Nullable.
To construct, see NOTES section for EVENTS properties and create a hash table.
The collection of open extensions defined for the user.
Read-only.
Supports $expand.
Nullable.
To construct, see NOTES section for EXTENSIONS properties and create a hash table.
For a guest invited to the tenant using the invitation API, this property represents the invited user's invitation status.
For invited users, the state can be PendingAcceptance or Accepted, or null for all other users.
Requires $select to retrieve.
Supports $filter (eq, ne, not , in).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ExternalUserStateChangeDateTime
Shows the timestamp for the latest change to the externalUserState property.
Requires $select to retrieve.
Supports $filter (eq, ne, not , in).
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-FaxNumber
The fax number of the user.
Requires $select to retrieve.
Supports $filter (eq, ne, not , ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-FollowedSites
To construct, see NOTES section for FOLLOWEDSITES properties and create a hash table.
The given name (first name) of the user.
Maximum length is 64 characters.
Returned by default.
Supports $filter (eq, ne, not , ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Headers
Optional headers that will be added to the request.
Parameter properties
Type:
System.Collections.IDictionary
Supports wildcards:
False
DontShow:
False
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
True
Value from pipeline by property name:
False
Value from remaining arguments:
False
-HireDate
The hire date of the user.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014, is 2014-01-01T00:00:00Z.
Requires $select to retrieve.
Note: This property is specific to SharePoint in Microsoft 365.
We recommend using the native employeeHireDate property to set and update hire date values using Microsoft Graph APIs.
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-HttpPipelineAppend
SendAsync Pipeline Steps to be appended to the front of the pipeline
Represents the identities that can be used to sign in to this user account.
Microsoft (also known as a local account), organizations, or social identity providers such as Facebook, Google, and Microsoft can provide identity and tie it to a user account.
It might contain multiple items with the same signInType value.
Requires $select to retrieve.
Supports $filter (eq) with limitations.
To construct, see NOTES section for IDENTITIES properties and create a hash table.
Update the properties of a user object.
To use this API to update an agentUser, specify an @odata.type property with a value of #microsoft.graph.agentUser in the request body.
The instant message voice-over IP (VOIP) session initiation protocol (SIP) addresses for the user.
Read-only.
Requires $select to retrieve.
Supports $filter (eq, not, ge, le, startsWith).
Parameter properties
Type:
System.String[]
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-InferenceClassification
inferenceClassification
To construct, see NOTES section for INFERENCECLASSIFICATION properties and create a hash table.
Identity Parameter
To construct, see NOTES section for INPUTOBJECT properties and create a hash table.
Parameter properties
Type:
Microsoft.Graph.PowerShell.Models.IUsersIdentity
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
True
Value from pipeline:
True
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateViaIdentity
Position:
Named
Mandatory:
True
Value from pipeline:
True
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Insights
itemInsights
Parameter properties
Type:
System.Collections.Hashtable
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Interests
A list for the user to describe their interests.
Requires $select to retrieve.
Parameter properties
Type:
System.String[]
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-IsManagementRestricted
true if the user is a member of a restricted management administrative unit.
If not set, the default value is null and the default behavior is false.
Read-only.
To manage a user who is a member of a restricted management administrative unit, the administrator or calling app must be assigned a Microsoft Entra role at the scope of the restricted management administrative unit.
Requires $select to retrieve.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-IsResourceAccount
Don't use – reserved for future use.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-JobTitle
The user's job title.
Maximum length is 128 characters.
Returned by default.
Supports $filter (eq, ne, not , ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-JoinedTeams
To construct, see NOTES section for JOINEDTEAMS properties and create a hash table.
The time when this Microsoft Entra user last changed their password or when their password was created, whichever date the latest action was performed.
The date and time information uses ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Requires $select to retrieve.
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-LegalAgeGroupClassification
Used by enterprise applications to determine the legal age group of the user.
This property is read-only and calculated based on ageGroup and consentProvidedForMinor properties.
Allowed values: null, Undefined, MinorWithOutParentalConsent, MinorWithParentalConsent, MinorNoParentalConsentRequired, NotAdult, and Adult.
For more information, see legal age group property definitions.
Requires $select to retrieve.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-LicenseAssignmentStates
State of license assignments for this user.
Also indicates licenses that are directly assigned or the user inherited through group memberships.
Read-only.
Requires $select to retrieve.
To construct, see NOTES section for LICENSEASSIGNMENTSTATES properties and create a hash table.
The SMTP address for the user, for example, jeff@contoso.com.
Changes to this property update the user's proxyAddresses collection to include the value as an SMTP address.
This property can't contain accent characters.
NOTE: We don't recommend updating this property for Azure AD B2C user profiles.
Use the otherMails property instead.
Returned by default.
Supports $filter (eq, ne, not, ge, le, in, startsWith, endsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-MailboxSettings
mailboxSettings
To construct, see NOTES section for MAILBOXSETTINGS properties and create a hash table.
The mail alias for the user.
This property must be specified when a user is created.
Maximum length is 64 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ManagedAppRegistrations
Zero or more managed app registrations that belong to the user.
To construct, see NOTES section for MANAGEDAPPREGISTRATIONS properties and create a hash table.
The groups and directory roles that the user is a member of.
Read-only.
Nullable.
Supports $expand.
To construct, see NOTES section for MEMBEROF properties and create a hash table.
The primary cellular telephone number for the user.
Read-only for users synced from the on-premises directory.
Maximum length is 64 characters.
Returned by default.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values) and $search.
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-MySite
The URL for the user's site.
Requires $select to retrieve.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Notes
The notes in the user's Notes folder.
Read-only.
Nullable.
To construct, see NOTES section for NOTES properties and create a hash table.
The office location in the user's place of business.
Returned by default.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Onenote
onenote
To construct, see NOTES section for ONENOTE properties and create a hash table.
Information about a meeting, including the URL used to join a meeting, the attendees list, and the description.
To construct, see NOTES section for ONLINEMEETINGS properties and create a hash table.
Contains the on-premises Active Directory distinguished name or DN.
The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Microsoft Entra Connect.
Read-only.
Requires $select to retrieve.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesDomainName
Contains the on-premises domainFQDN, also called dnsDomainName synchronized from the on-premises directory.
The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Microsoft Entra Connect.
Read-only.
Requires $select to retrieve.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesExtensionAttributes
onPremisesExtensionAttributes
To construct, see NOTES section for ONPREMISESEXTENSIONATTRIBUTES properties and create a hash table.
This property is used to associate an on-premises Active Directory user account to their Microsoft Entra user object.
This property must be specified when creating a new user account in the Graph if you're using a federated domain for the user's userPrincipalName (UPN) property.
NOTE: The $ and _ characters can't be used when specifying this property.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in).
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesLastSyncDateTime
Indicates the last time at which the object was synced with the on-premises directory; for example: 2013-02-16T03:04:54Z.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in).
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesProvisioningErrors
Errors when using Microsoft synchronization product during provisioning.
Requires $select to retrieve.
Supports $filter (eq, not, ge, le).
To construct, see NOTES section for ONPREMISESPROVISIONINGERRORS properties and create a hash table.
Contains the on-premises samAccountName synchronized from the on-premises directory.
The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Microsoft Entra Connect.
Read-only.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesSecurityIdentifier
Contains the on-premises security identifier (SID) for the user that was synchronized from on-premises to the cloud.
Read-only.
Requires $select to retrieve.
Supports $filter (eq including on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesSyncBehavior
onPremisesSyncBehavior
To construct, see NOTES section for ONPREMISESSYNCBEHAVIOR properties and create a hash table.
true if this user object is currently being synced from an on-premises Active Directory (AD); otherwise the user isn't being synced and can be managed in Microsoft Entra ID.
Read-only.
Requires $select to retrieve.
Supports $filter (eq, ne, not, in, and eq on null values).
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OnPremisesUserPrincipalName
Contains the on-premises userPrincipalName synchronized from the on-premises directory.
The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Microsoft Entra Connect.
Read-only.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-OtherMails
A list of other email addresses for the user; for example: ['bob@contoso.com', 'Robert@fabrikam.com'].
Can store up to 250 values, each with a limit of 250 characters.
NOTE: This property can't contain accent characters.
Requires $select to retrieve.
Supports $filter (eq, not, ge, le, in, startsWith, endsWith, /$count eq 0, /$count ne 0).
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
Parameter properties
Type:
System.String[]
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Outlook
outlookUser
To construct, see NOTES section for OUTLOOK properties and create a hash table.
Devices the user owns.
Read-only.
Nullable.
Supports $expand and $filter (/$count eq 0, /$count ne 0, /$count eq 1, /$count ne 1).
To construct, see NOTES section for OWNEDDEVICES properties and create a hash table.
Directory objects the user owns.
Read-only.
Nullable.
Supports $expand, $select nested in $expand, and $filter (/$count eq 0, /$count ne 0, /$count eq 1, /$count ne 1).
To construct, see NOTES section for OWNEDOBJECTS properties and create a hash table.
Specifies password policies for the user.
This value is an enumeration with one possible value being DisableStrongPassword, which allows weaker passwords than the default policy to be specified.
DisablePasswordExpiration can also be specified.
The two might be specified together; for example: DisablePasswordExpiration, DisableStrongPassword.
Requires $select to retrieve.
For more information on the default password policies, see Microsoft Entra password policies.
Supports $filter (ne, not, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-PasswordProfile
passwordProfile
To construct, see NOTES section for PASSWORDPROFILE properties and create a hash table.
The collection of the user's profile photos in different sizes.
Read-only.
To construct, see NOTES section for PHOTOS properties and create a hash table.
The postal code for the user's postal address.
The postal code is specific to the user's country or region.
In the United States of America, this attribute contains the ZIP code.
Maximum length is 40 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-PreferredDataLocation
The preferred data location for the user.
For more information, see OneDrive Online Multi-Geo.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-PreferredLanguage
The preferred language for the user.
The preferred language format is based on RFC 4646.
The name is a combination of an ISO 639 two-letter lowercase culture code associated with the language, and an ISO 3166 two-letter uppercase subculture code associated with the country or region.
Example: 'en-US', or 'es-ES'.
Returned by default.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values)
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-PreferredName
The preferred name for the user.
Not Supported.
This attribute returns an empty string.Requires $select to retrieve.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Presence
presence
To construct, see NOTES section for PRESENCE properties and create a hash table.
The plans that are provisioned for the user.
Read-only.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq, not, ge, le).
To construct, see NOTES section for PROVISIONEDPLANS properties and create a hash table.
For example: ['SMTP: bob@contoso.com', 'smtp: bob@sales.contoso.com'].
Changes to the mail property update this collection to include the value as an SMTP address.
For more information, see mail and proxyAddresses properties.
The proxy address prefixed with SMTP (capitalized) is the primary proxy address, while those addresses prefixed with smtp are the secondary proxy addresses.
For Azure AD B2C accounts, this property has a limit of 10 unique addresses.
Read-only in Microsoft Graph; you can update this property only through the Microsoft 365 admin center.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq, not, ge, le, startsWith, endsWith, /$count eq 0, /$count ne 0).
Parameter properties
Type:
System.String[]
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ProxyCredential
Credentials for a proxy server to use for the remote call
Parameter properties
Type:
System.Management.Automation.PSCredential
Supports wildcards:
False
DontShow:
False
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ProxyUseDefaultCredentials
Use the default credentials for the proxy
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-RegisteredDevices
Devices that are registered for the user.
Read-only.
Nullable.
Supports $expand and returns up to 100 objects.
To construct, see NOTES section for REGISTEREDDEVICES properties and create a hash table.
Security identifier (SID) of the user, used in Windows scenarios.
Read-only.
Returned by default.
Supports $select and $filter (eq, not, ge, le, startsWith).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-ServiceProvisioningErrors
Errors published by a federated service describing a nontransient, service-specific error regarding the properties or link from a user object.
Supports $filter (eq, not, for isResolved and serviceInstance).
To construct, see NOTES section for SERVICEPROVISIONINGERRORS properties and create a hash table.
Do not use in Microsoft Graph.
Manage this property through the Microsoft 365 admin center instead.
Represents whether the user should be included in the Outlook global address list.
See Known issue.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-SignInActivity
signInActivity
To construct, see NOTES section for SIGNINACTIVITY properties and create a hash table.
Any refresh tokens or session tokens (session cookies) issued before this time are invalid.
Applications get an error when using an invalid refresh or session token to acquire a delegated access token (to access APIs such as Microsoft Graph).
If this happens, the application needs to acquire a new refresh token by requesting the authorized endpoint.
Read-only.
Use revokeSignInSessions to reset.
Requires $select to retrieve.
Parameter properties
Type:
System.DateTime
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Skills
A list for the user to enumerate their skills.
Requires $select to retrieve.
Parameter properties
Type:
System.String[]
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Solutions
userSolutionRoot
To construct, see NOTES section for SOLUTIONS properties and create a hash table.
Directory objects that this user sponsors, such as guest users, agent users, agent blueprints, agent blueprint principals, and agent identities.
If the user is a member of a group that's a sponsor, the objects sponsored by that group are also included.
Read-only.
Nullable.
Supports $filter, $count, $select, $expand, $top, and $skip.
To construct, see NOTES section for SPONSOROF properties and create a hash table.
The users and groups responsible for this guest's privileges in the tenant and keeping the guest's information and access updated.
(HTTP Methods: GET, POST, DELETE.).
Supports $expand.
To construct, see NOTES section for SPONSORS properties and create a hash table.
The state or province in the user's address.
Maximum length is 128 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-StreetAddress
The street address of the user's place of business.
Maximum length is 1,024 characters.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Surname
The user's surname (family name or last name).
Maximum length is 64 characters.
Returned by default.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Teamwork
userTeamwork
To construct, see NOTES section for TEAMWORK properties and create a hash table.
The groups, including nested groups, and directory roles that a user is a member of.
Nullable.
To construct, see NOTES section for TRANSITIVEMEMBEROF properties and create a hash table.
A two-letter country code (ISO standard 3166).
Required for users that are assigned licenses due to legal requirements to check for availability of services in countries/regions.
Examples include: US, JP, and GB.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-UserId
The unique identifier of user
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateExpanded
Position:
Named
Mandatory:
True
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
Update
Position:
Named
Mandatory:
True
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-UserPrincipalName
The user principal name (UPN) of the user.
The UPN is an Internet-style sign-in name for the user based on the Internet standard RFC 822.
By convention, this value should map to the user's email name.
The general format is alias@domain, where the domain must be present in the tenant's collection of verified domains.
This property is required when a user is created.
The verified domains for the tenant can be accessed from the verifiedDomains property of organization.NOTE: This property can't contain accent characters.
Only the following characters are allowed A - Z, a - z, 0 - 9, ', ., -, _, !, #, ^, ~,
For the complete list of allowed characters, see username policies.
Returned by default.
Supports $filter (eq, ne, not, ge, le, in, startsWith, endsWith) and $orderby.
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-UserType
A string value that can be used to classify user types in your directory.
The possible values are Member and Guest.
Requires $select to retrieve.
Supports $filter (eq, ne, not, in, and eq on null values).
NOTE: For more information about the permissions for members and guests, see What are the default user permissions in Microsoft Entra ID
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
UpdateViaIdentityExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
UpdateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-WhatIf
Runs the command in a mode that only reports what would happen without performing the actions.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Supports wildcards:
False
DontShow:
False
Aliases:
wi
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable,
-InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable,
-ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see
about_CommonParameters.
To create the parameters described below, construct a hash table containing the appropriate properties.
For information on hash tables, run Get-Help about_Hash_Tables.
ACTIVITIES : The user's activities across devices.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[ActivationUrl ]: Required.
URL used to launch the activity in the best native experience represented by the appId.
Might launch a web-based app if no native app exists.
[ActivitySourceHost ]: Required.
URL for the domain representing the cross-platform identity mapping for the app.
Mapping is stored either as a JSON file hosted on the domain or configurable via Windows Dev Center.
The JSON file is named cross-platform-app-identifiers and is hosted at root of your HTTPS domain, either at the top level domain or include a sub domain.
For example: https://contoso.com or https://myapp.contoso.com but NOT https://myapp.contoso.com/somepath.
You must have a unique file and domain (or sub domain) per cross-platform app identity.
For example, a separate file and domain is needed for Word vs.
PowerPoint.
[AppActivityId ]: Required.
The unique activity ID in the context of the app - supplied by caller and immutable thereafter.
[AppDisplayName ]: Optional.
Short text description of the app used to generate the activity for use in cases when the app is not installed on the user’s local device.
[ContentInfo ]: Standard way to represent a Json blob on Graph.
[(Any)
ADHOCCALLS : Ad hoc calls associated with the user.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[Recordings ]: The recordings of a call.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[CallId ]: The unique identifier for the call that is related to this recording.
Read-only.
[Content ]: The content of the recording.
Read-only.
[ContentCorrelationId ]: The unique identifier that links the transcript with its corresponding recording.
Read-only.
[CreatedDateTime ]: Date and time at which the recording was created.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[EndDateTime ]: Date and time at which the recording ends.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[MeetingId ]: The unique identifier of the onlineMeeting related to this recording.
Read-only.
[MeetingOrganizer ]: identitySet
[(Any) ]: This indicates any property can be added to this object.
[Application ]: identity
[(Any) ]: This indicates any property can be added to this object.
[DisplayName ]: The display name of the identity.For drive items, the display name might not always be available or up to date.
For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta.
[Id ]: Unique identifier for the identity or actor.
For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review.
[Device ]: identity
[User ]: identity
[RecordingContentUrl ]: The URL that can be used to access the content of the recording.
Read-only.
[Transcripts ]: The transcripts of a call.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[CallId ]: The unique identifier for the call that is related to this transcript.
Read-only.
[Content ]: The content of the transcript.
Read-only.
[ContentCorrelationId ]: The unique identifier that links the transcript with its corresponding recording.
Read-only.
[CreatedDateTime ]: Date and time at which the transcript was created.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[EndDateTime ]: Date and time at which the transcription ends.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[MeetingId ]: The unique identifier of the online meeting related to this transcript.
Read-only.
[MeetingOrganizer ]: identitySet
[MetadataContent ]: The time-aligned metadata of the utterances in the transcript.
Read-only.
[TranscriptContentUrl ]: The URL that can be used to access the content of the transcript.
Read-only.
AGREEMENTACCEPTANCES : The user's terms of use acceptance statuses.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[AgreementFileId ]: The identifier of the agreement file accepted by the user.
[AgreementId ]: The identifier of the agreement.
[DeviceDisplayName ]: The display name of the device used for accepting the agreement.
[DeviceId ]: The unique identifier of the device used for accepting the agreement.
Supports $filter (eq) and eq for null values.
[DeviceOSType ]: The operating system used to accept the agreement.
[DeviceOSVersion ]: The operating system version of the device used to accept the agreement.
[ExpirationDateTime ]: The expiration date time of the acceptance.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Supports $filter (eq, ge, le) and eq for null values.
[RecordedDateTime ]: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[State ]: agreementAcceptanceState
[UserDisplayName ]: Display name of the user when the acceptance was recorded.
[UserEmail ]: Email of the user when the acceptance was recorded.
[UserId ]: The identifier of the user who accepted the agreement.
Supports $filter (eq).
[UserPrincipalName ]: UPN of the user when the acceptance was recorded.
APPROLEASSIGNMENTS : Represents the app roles a user is granted for an application.
Supports $expand.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Id ]: The unique identifier for an entity.
Read-only.
[AppRoleId ]: The identifier (id) for the app role that's assigned to the principal.
This app role must be exposed in the appRoles property on the resource application's service principal (resourceId).
If the resource application hasn't declared any app roles, a default app role ID of 00000000-0000-0000-0000-000000000000 can be specified to signal that the principal is assigned to the resource app without any specific app roles.
Required on create.
[CreatedDateTime ]: The time when the app role assignment was created.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[PrincipalDisplayName ]: The display name of the user, group, or service principal that was granted the app role assignment.
Maximum length is 256 characters.
Read-only.
Supports $filter (eq and startswith).
[PrincipalId ]: The unique identifier (id) for the user, security group, or service principal being granted the app role.
Security groups with dynamic memberships are supported.
Required on create.
[PrincipalType ]: The type of the assigned principal.
This can either be User, Group, or ServicePrincipal.
Read-only.
[ResourceDisplayName ]: The display name of the resource app's service principal to which the assignment is made.
Maximum length is 256 characters.
[ResourceId ]: The unique identifier (id) for the resource service principal for which the assignment is made.
Required on create.
Supports $filter (eq only).
ASSIGNEDLICENSES : The licenses that are assigned to the user, including inherited (group-based) licenses.
This property doesn't differentiate between directly assigned and inherited licenses.
Use the licenseAssignmentStates property to identify the directly assigned and inherited licenses.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq, not, /$count eq 0, /$count ne 0).
[DisabledPlans ]: A collection of the unique identifiers for plans that have been disabled.
IDs are available in servicePlans > servicePlanId in the tenant's subscribedSkus or serviceStatus > servicePlanId in the tenant's companySubscription.
[SkuId ]: The unique identifier for the SKU.
Corresponds to the skuId from subscribedSkus or companySubscription.
ASSIGNEDPLANS : The plans that are assigned to the user.
Read-only.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq and not).
[AssignedDateTime ]: The date and time at which the plan was assigned.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[CapabilityStatus ]: Condition of the capability assignment.
The possible values are Enabled, Warning, Suspended, Deleted, LockedOut.
See a detailed description of each value.
[Service ]: The name of the service; for example, exchange.
[ServicePlanId ]: A GUID that identifies the service plan.
For a complete list of GUIDs and their equivalent friendly service names, see Product names and service plan identifiers for licensing.
AUTHENTICATION : authentication
[(Any) ]: This indicates any property can be added to this object.
[Id ]: The unique identifier for an entity.
Read-only.
[EmailMethods ]: The email address registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[EmailAddress ]: The email address registered to this user.
[ExternalAuthenticationMethods ]: Represents the external MFA registered to a user for authentication using an external identity provider.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[ConfigurationId ]: A unique identifier used to manage the external auth method within Microsoft Entra ID.
[DisplayName ]: Custom name given to the registered external MFA.
[Fido2Methods ]: Represents the FIDO2 security keys registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[AaGuid ]: Authenticator Attestation GUID, an identifier that indicates the type (such as make and model) of the authenticator.
[AttestationCertificates ]: The attestation certificate or certificates attached to this passkey.
[AttestationLevel ]: attestationLevel
[DisplayName ]: The display name of the key as given by the user.
[Model ]: The manufacturer-assigned model of the FIDO2 passkey.
[PasskeyType ]: passkeyType
[PublicKeyCredential ]: webauthnPublicKeyCredential
[(Any) ]: This indicates any property can be added to this object.
[ClientExtensionResults ]: webauthnAuthenticationExtensionsClientOutputs
[(Any) ]: This indicates any property can be added to this object.
[Id ]: The credential ID created by the WebAuthn Authenticator.
This value is Base64URL-encoded without padding.
[Response ]: webauthnAuthenticatorAttestationResponse
[(Any) ]: This indicates any property can be added to this object.
[AttestationObject ]: A CBOR-encoded attestation object containing the authenticator data and attestation statement.
This value is Base64URL-encoded without padding.
[ClientDataJson ]: Contains the JSON-compatible serialization of client data passed to the authenticator by the client.
This value is Base64URL-encoded without padding.
[Methods ]: Represents all authentication methods registered to a user.
[Id ]: The unique identifier for an entity.
Read-only.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[MicrosoftAuthenticatorMethods ]: The details of the Microsoft Authenticator app registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Device ]: device
[(Any) ]: This indicates any property can be added to this object.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Id ]: The unique identifier for an entity.
Read-only.
[AccountEnabled ]: true if the account is enabled; otherwise, false.
Required.
Default is true.
Supports $filter (eq, ne, not, in).
Only callers with at least the Cloud Device Administrator role can set this property.
[AlternativeSecurityIds ]: For internal use only.
Not nullable.
Supports $filter (eq, not, ge, le).
[IdentityProvider ]: For internal use only.
[Key ]: For internal use only.
[Type ]: For internal use only.
[ApproximateLastSignInDateTime ]: The timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
Supports $filter (eq, ne, not, ge, le, and eq on null values) and $orderby.
[ComplianceExpirationDateTime ]: The timestamp when the device is no longer deemed compliant.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[DeviceCategory ]: User-defined property set by Intune to automatically add devices to groups and simplify managing devices.
[DeviceId ]: Unique identifier set by Azure Device Registration Service at the time of registration.
This alternate key can be used to reference the device object.
Supports $filter (eq, ne, not, startsWith).
[DeviceMetadata ]: For internal use only.
Set to null.
[DeviceOwnership ]: Ownership of the device.
Intune sets this property.
The possible values are: unknown, company, personal.
[DeviceVersion ]: For internal use only.
[DisplayName ]: The display name for the device.
Maximum length is 256 characters.
Required.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values), $search, and $orderby.
[EnrollmentProfileName ]: Enrollment profile applied to the device.
For example, Apple Device Enrollment Profile, Device enrollment - Corporate device identifiers, or Windows Autopilot profile name.
This property is set by Intune.
[EnrollmentType ]: Enrollment type of the device.
Intune sets this property.
The possible values are: unknown, userEnrollment, deviceEnrollmentManager, appleBulkWithUser, appleBulkWithoutUser, windowsAzureADJoin, windowsBulkUserless, windowsAutoEnrollment, windowsBulkAzureDomainJoin, windowsCoManagement, windowsAzureADJoinUsingDeviceAuth,appleUserEnrollment, appleUserEnrollmentWithServiceAccount.
NOTE: This property might return other values apart from those listed.
[Extensions ]: The collection of open extensions defined for the device.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[IsCompliant ]: true if the device complies with Mobile Device Management (MDM) policies; otherwise, false.
Read-only.
This can only be updated by Intune for any device OS type or by an approved MDM app for Windows OS devices.
Supports $filter (eq, ne, not).
[IsManaged ]: true if the device is managed by a Mobile Device Management (MDM) app; otherwise, false.
This can only be updated by Intune for any device OS type or by an approved MDM app for Windows OS devices.
Supports $filter (eq, ne, not).
[IsManagementRestricted ]: Indicates whether the device is a member of a restricted management administrative unit.
If not set, the default value is null and the default behavior is false.
Read-only.
To manage a device that's a member of a restricted management administrative unit, the administrator or calling app must be assigned a Microsoft Entra role at the scope of the restricted management administrative unit.
Requires $select to retrieve.
[IsRooted ]: true if the device is rooted or jail-broken.
This property can only be updated by Intune.
[ManagementType ]: The management channel of the device.
This property is set by Intune.
The possible values are: eas, mdm, easMdm, intuneClient, easIntuneClient, configurationManagerClient, configurationManagerClientMdm, configurationManagerClientMdmEas, unknown, jamf, googleCloudDevicePolicyController.
[Manufacturer ]: Manufacturer of the device.
Read-only.
[MdmAppId ]: Application identifier used to register device into MDM.
Read-only.
Supports $filter (eq, ne, not, startsWith).
[MemberOf ]: Groups and administrative units that this device is a member of.
Read-only.
Nullable.
Supports $expand.
[Id ]: The unique identifier for an entity.
Read-only.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Model ]: Model of the device.
Read-only.
[OnPremisesLastSyncDateTime ]: The last time at which the object was synced with the on-premises directory.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z Read-only.
Supports $filter (eq, ne, not, ge, le, in).
[OnPremisesSecurityIdentifier ]: The on-premises security identifier (SID) for the user who was synchronized from on-premises to the cloud.
Read-only.
Requires $select to retrieve.
Supports $filter (eq).
[OnPremisesSyncEnabled ]: true if this object is synced from an on-premises directory; false if this object was originally synced from an on-premises directory but is no longer synced; null if this object has never been synced from an on-premises directory (default).
Read-only.
Supports $filter (eq, ne, not, in, and eq on null values).
[OperatingSystem ]: The type of operating system on the device.
Required.
Supports $filter (eq, ne, not, ge, le, startsWith, and eq on null values).
[OperatingSystemVersion ]: The version of the operating system on the device.
Required.
Supports $filter (eq, ne, not, ge, le, startsWith, and eq on null values).
[PhysicalIds ]: For internal use only.
Not nullable.
Supports $filter (eq, not, ge, le, startsWith,/$count eq 0, /$count ne 0).
[ProfileType ]: The profile type of the device.
Possible values: RegisteredDevice (default), SecureVM, Printer, Shared, IoT.
[RegisteredOwners ]: The user that cloud joined the device or registered their personal device.
The registered owner is set at the time of registration.
Read-only.
Nullable.
Supports $expand.
[RegisteredUsers ]: Collection of registered users of the device.
For cloud joined devices and registered personal devices, registered users are set to the same value as registered owners at the time of registration.
Read-only.
Nullable.
Supports $expand.
[RegistrationDateTime ]: Date and time of when the device was registered.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[SystemLabels ]: List of labels applied to the device by the system.
Supports $filter (/$count eq 0, /$count ne 0).
[TransitiveMemberOf ]: Groups and administrative units that the device is a member of.
This operation is transitive.
Supports $expand.
[TrustType ]: Type of trust for the joined device.
Read-only.
Possible values: Workplace (indicates bring your own personal devices), AzureAd (Cloud-only joined devices), ServerAd (on-premises domain joined devices joined to Microsoft Entra ID).
For more information, see Introduction to device management in Microsoft Entra ID.
Supports $filter (eq, ne, not, in).
[DeviceTag ]: Tags containing app metadata.
[DisplayName ]: The name of the device on which this app is registered.
[PhoneAppVersion ]: Numerical version of this instance of the Authenticator app.
[Operations ]: Represents the status of a long-running operation, such as a password reset operation.
[Id ]: The unique identifier for an entity.
Read-only.
[CreatedDateTime ]: The start time of the operation.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[LastActionDateTime ]: The time of the last action in the operation.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[ResourceLocation ]: URI of the resource that the operation is performed on.
[Status ]: longRunningOperationStatus
[StatusDetail ]: Details about the status of the operation.
[PasswordMethods ]: Represents the password registered to a user for authentication.
For security, the password itself is never returned in the object, but action can be taken to reset a password.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Password ]: For security, the password is always returned as null from a LIST or GET operation.
[PhoneMethods ]: The phone numbers registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[PhoneNumber ]: The phone number to text or call for authentication.
Phone numbers use the format +{country code} {number}x{extension}, with extension optional.
For example, +1 5555551234 or +1 5555551234x123 are valid.
Numbers are rejected when creating or updating if they don't match the required format.
[PhoneType ]: authenticationPhoneType
[SmsSignInState ]: authenticationMethodSignInState
[PlatformCredentialMethods ]: Represents a platform credential instance registered to a user on Mac OS.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Device ]: device
[DisplayName ]: The name of the device on which Platform Credential is registered.
[KeyStrength ]: authenticationMethodKeyStrength
[Platform ]: authenticationMethodPlatform
[SoftwareOathMethods ]: The software OATH time-based one-time password (TOTP) applications registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[SecretKey ]: The secret key of the method.
Always returns null.
[TemporaryAccessPassMethods ]: Represents a Temporary Access Pass registered to a user for authentication through time-limited passcodes.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[IsUsable ]: The state of the authentication method that indicates whether it's currently usable by the user.
[IsUsableOnce ]: Determines whether the pass is limited to a one-time use.
If true, the pass can be used once; if false, the pass can be used multiple times within the Temporary Access Pass lifetime.
[LifetimeInMinutes ]: The lifetime of the Temporary Access Pass in minutes starting at startDateTime.
Must be between 10 and 43200 inclusive (equivalent to 30 days).
[MethodUsabilityReason ]: Details about the usability state (isUsable).
Reasons can include: EnabledByPolicy, DisabledByPolicy, Expired, NotYetValid, OneTimeUsed.
[StartDateTime ]: The date and time when the Temporary Access Pass becomes available to use and when isUsable is true is enforced.
[TemporaryAccessPass ]: The Temporary Access Pass used to authenticate.
Returned only on creation of a new temporaryAccessPassAuthenticationMethod object; Hidden in subsequent read operations and returned as null with GET.
[WindowsHelloForBusinessMethods ]: Represents the Windows Hello for Business authentication method registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Device ]: device
[DisplayName ]: The name of the device on which Windows Hello for Business is registered
[KeyStrength ]: authenticationMethodKeyStrength
AUTHORIZATIONINFO : authorizationInfo
[(Any) ]: This indicates any property can be added to this object.
[CertificateUserIds ]:
BODYPARAMETER : user
[(Any) ]: This indicates any property can be added to this object.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Id ]: The unique identifier for an entity.
Read-only.
[AboutMe ]: A freeform text entry field for the user to describe themselves.
Requires $select to retrieve.
[AccountEnabled ]: true if the account is enabled; otherwise, false.
This property is required when a user is created.
Requires $select to retrieve.
Supports $filter (eq, ne, not, and in).
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
[Activities ]: The user's activities across devices.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[ActivationUrl ]: Required.
URL used to launch the activity in the best native experience represented by the appId.
Might launch a web-based app if no native app exists.
[ActivitySourceHost ]: Required.
URL for the domain representing the cross-platform identity mapping for the app.
Mapping is stored either as a JSON file hosted on the domain or configurable via Windows Dev Center.
The JSON file is named cross-platform-app-identifiers and is hosted at root of your HTTPS domain, either at the top level domain or include a sub domain.
For example: https://contoso.com or https://myapp.contoso.com but NOT https://myapp.contoso.com/somepath.
You must have a unique file and domain (or sub domain) per cross-platform app identity.
For example, a separate file and domain is needed for Word vs.
PowerPoint.
[AppActivityId ]: Required.
The unique activity ID in the context of the app - supplied by caller and immutable thereafter.
[AppDisplayName ]: Optional.
Short text description of the app used to generate the activity for use in cases when the app is not installed on the user’s local device.
[ContentInfo ]: Standard way to represent a Json blob on Graph.
[(Any) ]: This indicates any property can be added to this object.
[ContentUrl ]: Optional.
Used in the event the content can be rendered outside of a native or web-based app experience (for example, a pointer to an item in an RSS feed).
[CreatedDateTime ]: Set by the server.
DateTime in UTC when the object was created on the server.
[ExpirationDateTime ]: Set by the server.
DateTime in UTC when the object expired on the server.
[FallbackUrl ]: Optional.
URL used to launch the activity in a web-based app, if available.
[HistoryItems ]: Optional.
NavigationProperty/Containment; navigation property to the activity's historyItems.
[Id ]: The unique identifier for an entity.
Read-only.
[ActiveDurationSeconds ]: Optional.
The duration of active user engagement.
if not supplied, this is calculated from the startedDateTime and lastActiveDateTime.
[Activity ]: userActivity
[CreatedDateTime ]: Set by the server.
DateTime in UTC when the object was created on the server.
[ExpirationDateTime ]: Optional.
UTC DateTime when the activityHistoryItem will undergo hard-delete.
Can be set by the client.
[LastActiveDateTime ]: Optional.
UTC DateTime when the activityHistoryItem (activity session) was last understood as active or finished - if null, activityHistoryItem status should be Ongoing.
[LastModifiedDateTime ]: Set by the server.
DateTime in UTC when the object was modified on the server.
[StartedDateTime ]: Required.
UTC DateTime when the activityHistoryItem (activity session) was started.
Required for timeline history.
[Status ]: status
[UserTimezone ]: Optional.
The timezone in which the user's device used to generate the activity was located at activity creation time.
Values supplied as Olson IDs in order to support cross-platform representation.
[LastModifiedDateTime ]: Set by the server.
DateTime in UTC when the object was modified on the server.
[Status ]: status
[UserTimezone ]: Optional.
The timezone in which the user's device used to generate the activity was located at activity creation time; values supplied as Olson IDs in order to support cross-platform representation.
[VisualElements ]: visualInfo
[(Any) ]: This indicates any property can be added to this object.
[Attribution ]: imageInfo
[(Any) ]: This indicates any property can be added to this object.
[AddImageQuery ]: Optional; parameter used to indicate the server is able to render image dynamically in response to parameterization.
For example – a high contrast image
[AlternateText ]: Optional; alt-text accessible content for the image
[AlternativeText ]:
[IconUrl ]: Optional; URI that points to an icon which represents the application used to generate the activity
[BackgroundColor ]: Optional.
Background color used to render the activity in the UI - brand color for the application source of the activity.
Must be a valid hex color
[Content ]: Standard way to represent a Json blob on Graph.
[Description ]: Optional.
Longer text description of the user's unique activity (example: document name, first sentence, and/or metadata)
[DisplayText ]: Required.
Short text description of the user's unique activity (for example, document name in cases where an activity refers to document creation)
[AdhocCalls ]: Ad hoc calls associated with the user.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[Recordings ]: The recordings of a call.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[CallId ]: The unique identifier for the call that is related to this recording.
Read-only.
[Content ]: The content of the recording.
Read-only.
[ContentCorrelationId ]: The unique identifier that links the transcript with its corresponding recording.
Read-only.
[CreatedDateTime ]: Date and time at which the recording was created.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[EndDateTime ]: Date and time at which the recording ends.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[MeetingId ]: The unique identifier of the onlineMeeting related to this recording.
Read-only.
[MeetingOrganizer ]: identitySet
[(Any) ]: This indicates any property can be added to this object.
[Application ]: identity
[(Any) ]: This indicates any property can be added to this object.
[DisplayName ]: The display name of the identity.For drive items, the display name might not always be available or up to date.
For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta.
[Id ]: Unique identifier for the identity or actor.
For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review.
[Device ]: identity
[User ]: identity
[RecordingContentUrl ]: The URL that can be used to access the content of the recording.
Read-only.
[Transcripts ]: The transcripts of a call.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[CallId ]: The unique identifier for the call that is related to this transcript.
Read-only.
[Content ]: The content of the transcript.
Read-only.
[ContentCorrelationId ]: The unique identifier that links the transcript with its corresponding recording.
Read-only.
[CreatedDateTime ]: Date and time at which the transcript was created.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[EndDateTime ]: Date and time at which the transcription ends.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[MeetingId ]: The unique identifier of the online meeting related to this transcript.
Read-only.
[MeetingOrganizer ]: identitySet
[MetadataContent ]: The time-aligned metadata of the utterances in the transcript.
Read-only.
[TranscriptContentUrl ]: The URL that can be used to access the content of the transcript.
Read-only.
[AgeGroup ]: Sets the age group of the user.
Allowed values: null, Minor, NotAdult, and Adult.
For more information, see legal age group property definitions.
Requires $select to retrieve.
Supports $filter (eq, ne, not, and in).
[AgreementAcceptances ]: The user's terms of use acceptance statuses.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[AgreementFileId ]: The identifier of the agreement file accepted by the user.
[AgreementId ]: The identifier of the agreement.
[DeviceDisplayName ]: The display name of the device used for accepting the agreement.
[DeviceId ]: The unique identifier of the device used for accepting the agreement.
Supports $filter (eq) and eq for null values.
[DeviceOSType ]: The operating system used to accept the agreement.
[DeviceOSVersion ]: The operating system version of the device used to accept the agreement.
[ExpirationDateTime ]: The expiration date time of the acceptance.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Supports $filter (eq, ge, le) and eq for null values.
[RecordedDateTime ]: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[State ]: agreementAcceptanceState
[UserDisplayName ]: Display name of the user when the acceptance was recorded.
[UserEmail ]: Email of the user when the acceptance was recorded.
[UserId ]: The identifier of the user who accepted the agreement.
Supports $filter (eq).
[UserPrincipalName ]: UPN of the user when the acceptance was recorded.
[AppRoleAssignments ]: Represents the app roles a user is granted for an application.
Supports $expand.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Id ]: The unique identifier for an entity.
Read-only.
[AppRoleId ]: The identifier (id) for the app role that's assigned to the principal.
This app role must be exposed in the appRoles property on the resource application's service principal (resourceId).
If the resource application hasn't declared any app roles, a default app role ID of 00000000-0000-0000-0000-000000000000 can be specified to signal that the principal is assigned to the resource app without any specific app roles.
Required on create.
[CreatedDateTime ]: The time when the app role assignment was created.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[PrincipalDisplayName ]: The display name of the user, group, or service principal that was granted the app role assignment.
Maximum length is 256 characters.
Read-only.
Supports $filter (eq and startswith).
[PrincipalId ]: The unique identifier (id) for the user, security group, or service principal being granted the app role.
Security groups with dynamic memberships are supported.
Required on create.
[PrincipalType ]: The type of the assigned principal.
This can either be User, Group, or ServicePrincipal.
Read-only.
[ResourceDisplayName ]: The display name of the resource app's service principal to which the assignment is made.
Maximum length is 256 characters.
[ResourceId ]: The unique identifier (id) for the resource service principal for which the assignment is made.
Required on create.
Supports $filter (eq only).
[AssignedLicenses ]: The licenses that are assigned to the user, including inherited (group-based) licenses.
This property doesn't differentiate between directly assigned and inherited licenses.
Use the licenseAssignmentStates property to identify the directly assigned and inherited licenses.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq, not, /$count eq 0, /$count ne 0).
[DisabledPlans ]: A collection of the unique identifiers for plans that have been disabled.
IDs are available in servicePlans > servicePlanId in the tenant's subscribedSkus or serviceStatus > servicePlanId in the tenant's companySubscription.
[SkuId ]: The unique identifier for the SKU.
Corresponds to the skuId from subscribedSkus or companySubscription.
[AssignedPlans ]: The plans that are assigned to the user.
Read-only.
Not nullable.
Requires $select to retrieve.
Supports $filter (eq and not).
[AssignedDateTime ]: The date and time at which the plan was assigned.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[CapabilityStatus ]: Condition of the capability assignment.
The possible values are Enabled, Warning, Suspended, Deleted, LockedOut.
See a detailed description of each value.
[Service ]: The name of the service; for example, exchange.
[ServicePlanId ]: A GUID that identifies the service plan.
For a complete list of GUIDs and their equivalent friendly service names, see Product names and service plan identifiers for licensing.
[Authentication ]: authentication
[(Any) ]: This indicates any property can be added to this object.
[Id ]: The unique identifier for an entity.
Read-only.
[EmailMethods ]: The email address registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[EmailAddress ]: The email address registered to this user.
[ExternalAuthenticationMethods ]: Represents the external MFA registered to a user for authentication using an external identity provider.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[ConfigurationId ]: A unique identifier used to manage the external auth method within Microsoft Entra ID.
[DisplayName ]: Custom name given to the registered external MFA.
[Fido2Methods ]: Represents the FIDO2 security keys registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[AaGuid ]: Authenticator Attestation GUID, an identifier that indicates the type (such as make and model) of the authenticator.
[AttestationCertificates ]: The attestation certificate or certificates attached to this passkey.
[AttestationLevel ]: attestationLevel
[DisplayName ]: The display name of the key as given by the user.
[Model ]: The manufacturer-assigned model of the FIDO2 passkey.
[PasskeyType ]: passkeyType
[PublicKeyCredential ]: webauthnPublicKeyCredential
[(Any) ]: This indicates any property can be added to this object.
[ClientExtensionResults ]: webauthnAuthenticationExtensionsClientOutputs
[(Any) ]: This indicates any property can be added to this object.
[Id ]: The credential ID created by the WebAuthn Authenticator.
This value is Base64URL-encoded without padding.
[Response ]: webauthnAuthenticatorAttestationResponse
[(Any) ]: This indicates any property can be added to this object.
[AttestationObject ]: A CBOR-encoded attestation object containing the authenticator data and attestation statement.
This value is Base64URL-encoded without padding.
[ClientDataJson ]: Contains the JSON-compatible serialization of client data passed to the authenticator by the client.
This value is Base64URL-encoded without padding.
[Methods ]: Represents all authentication methods registered to a user.
[Id ]: The unique identifier for an entity.
Read-only.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[MicrosoftAuthenticatorMethods ]: The details of the Microsoft Authenticator app registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Device ]: device
[(Any) ]: This indicates any property can be added to this object.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Id ]: The unique identifier for an entity.
Read-only.
[AccountEnabled ]: true if the account is enabled; otherwise, false.
Required.
Default is true.
Supports $filter (eq, ne, not, in).
Only callers with at least the Cloud Device Administrator role can set this property.
[AlternativeSecurityIds ]: For internal use only.
Not nullable.
Supports $filter (eq, not, ge, le).
[IdentityProvider ]: For internal use only.
[Key ]: For internal use only.
[Type ]: For internal use only.
[ApproximateLastSignInDateTime ]: The timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
Supports $filter (eq, ne, not, ge, le, and eq on null values) and $orderby.
[ComplianceExpirationDateTime ]: The timestamp when the device is no longer deemed compliant.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[DeviceCategory ]: User-defined property set by Intune to automatically add devices to groups and simplify managing devices.
[DeviceId ]: Unique identifier set by Azure Device Registration Service at the time of registration.
This alternate key can be used to reference the device object.
Supports $filter (eq, ne, not, startsWith).
[DeviceMetadata ]: For internal use only.
Set to null.
[DeviceOwnership ]: Ownership of the device.
Intune sets this property.
The possible values are: unknown, company, personal.
[DeviceVersion ]: For internal use only.
[DisplayName ]: The display name for the device.
Maximum length is 256 characters.
Required.
Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values), $search, and $orderby.
[EnrollmentProfileName ]: Enrollment profile applied to the device.
For example, Apple Device Enrollment Profile, Device enrollment - Corporate device identifiers, or Windows Autopilot profile name.
This property is set by Intune.
[EnrollmentType ]: Enrollment type of the device.
Intune sets this property.
The possible values are: unknown, userEnrollment, deviceEnrollmentManager, appleBulkWithUser, appleBulkWithoutUser, windowsAzureADJoin, windowsBulkUserless, windowsAutoEnrollment, windowsBulkAzureDomainJoin, windowsCoManagement, windowsAzureADJoinUsingDeviceAuth,appleUserEnrollment, appleUserEnrollmentWithServiceAccount.
NOTE: This property might return other values apart from those listed.
[Extensions ]: The collection of open extensions defined for the device.
Read-only.
Nullable.
[Id ]: The unique identifier for an entity.
Read-only.
[IsCompliant ]: true if the device complies with Mobile Device Management (MDM) policies; otherwise, false.
Read-only.
This can only be updated by Intune for any device OS type or by an approved MDM app for Windows OS devices.
Supports $filter (eq, ne, not).
[IsManaged ]: true if the device is managed by a Mobile Device Management (MDM) app; otherwise, false.
This can only be updated by Intune for any device OS type or by an approved MDM app for Windows OS devices.
Supports $filter (eq, ne, not).
[IsManagementRestricted ]: Indicates whether the device is a member of a restricted management administrative unit.
If not set, the default value is null and the default behavior is false.
Read-only.
To manage a device that's a member of a restricted management administrative unit, the administrator or calling app must be assigned a Microsoft Entra role at the scope of the restricted management administrative unit.
Requires $select to retrieve.
[IsRooted ]: true if the device is rooted or jail-broken.
This property can only be updated by Intune.
[ManagementType ]: The management channel of the device.
This property is set by Intune.
The possible values are: eas, mdm, easMdm, intuneClient, easIntuneClient, configurationManagerClient, configurationManagerClientMdm, configurationManagerClientMdmEas, unknown, jamf, googleCloudDevicePolicyController.
[Manufacturer ]: Manufacturer of the device.
Read-only.
[MdmAppId ]: Application identifier used to register device into MDM.
Read-only.
Supports $filter (eq, ne, not, startsWith).
[MemberOf ]: Groups and administrative units that this device is a member of.
Read-only.
Nullable.
Supports $expand.
[Id ]: The unique identifier for an entity.
Read-only.
[DeletedDateTime ]: Date and time when this object was deleted.
Always null when the object hasn't been deleted.
[Model ]: Model of the device.
Read-only.
[OnPremisesLastSyncDateTime ]: The last time at which the object was synced with the on-premises directory.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z Read-only.
Supports $filter (eq, ne, not, ge, le, in).
[OnPremisesSecurityIdentifier ]: The on-premises security identifier (SID) for the user who was synchronized from on-premises to the cloud.
Read-only.
Requires $select to retrieve.
Supports $filter (eq).
[OnPremisesSyncEnabled ]: true if this object is synced from an on-premises directory; false if this object was originally synced from an on-premises directory but is no longer synced; null if this object has never been synced from an on-premises directory (default).
Read-only.
Supports $filter (eq, ne, not, in, and eq on null values).
[OperatingSystem ]: The type of operating system on the device.
Required.
Supports $filter (eq, ne, not, ge, le, startsWith, and eq on null values).
[OperatingSystemVersion ]: The version of the operating system on the device.
Required.
Supports $filter (eq, ne, not, ge, le, startsWith, and eq on null values).
[PhysicalIds ]: For internal use only.
Not nullable.
Supports $filter (eq, not, ge, le, startsWith,/$count eq 0, /$count ne 0).
[ProfileType ]: The profile type of the device.
Possible values: RegisteredDevice (default), SecureVM, Printer, Shared, IoT.
[RegisteredOwners ]: The user that cloud joined the device or registered their personal device.
The registered owner is set at the time of registration.
Read-only.
Nullable.
Supports $expand.
[RegisteredUsers ]: Collection of registered users of the device.
For cloud joined devices and registered personal devices, registered users are set to the same value as registered owners at the time of registration.
Read-only.
Nullable.
Supports $expand.
[RegistrationDateTime ]: Date and time of when the device was registered.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC time.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
Read-only.
[SystemLabels ]: List of labels applied to the device by the system.
Supports $filter (/$count eq 0, /$count ne 0).
[TransitiveMemberOf ]: Groups and administrative units that the device is a member of.
This operation is transitive.
Supports $expand.
[TrustType ]: Type of trust for the joined device.
Read-only.
Possible values: Workplace (indicates bring your own personal devices), AzureAd (Cloud-only joined devices), ServerAd (on-premises domain joined devices joined to Microsoft Entra ID).
For more information, see Introduction to device management in Microsoft Entra ID.
Supports $filter (eq, ne, not, in).
[DeviceTag ]: Tags containing app metadata.
[DisplayName ]: The name of the device on which this app is registered.
[PhoneAppVersion ]: Numerical version of this instance of the Authenticator app.
[Operations ]: Represents the status of a long-running operation, such as a password reset operation.
[Id ]: The unique identifier for an entity.
Read-only.
[CreatedDateTime ]: The start time of the operation.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[LastActionDateTime ]: The time of the last action in the operation.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
[ResourceLocation ]: URI of the resource that the operation is performed on.
[Status ]: longRunningOperationStatus
[StatusDetail ]: Details about the status of the operation.
[PasswordMethods ]: Represents the password registered to a user for authentication.
For security, the password itself is never returned in the object, but action can be taken to reset a password.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Password ]: For security, the password is always returned as null from a LIST or GET operation.
[PhoneMethods ]: The phone numbers registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[PhoneNumber ]: The phone number to text or call for authentication.
Phone numbers use the format +{country code} {number}x{extension}, with extension optional.
For example, +1 5555551234 or +1 5555551234x123 are valid.
Numbers are rejected when creating or updating if they don't match the required format.
[PhoneType ]: authenticationPhoneType
[SmsSignInState ]: authenticationMethodSignInState
[PlatformCredentialMethods ]: Represents a platform credential instance registered to a user on Mac OS.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Device ]: device
[DisplayName ]: The name of the device on which Platform Credential is registered.
[KeyStrength ]: authenticationMethodKeyStrength
[Platform ]: authenticationMethodPlatform
[SoftwareOathMethods ]: The software OATH time-based one-time password (TOTP) applications registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[SecretKey ]: The secret key of the method.
Always returns null.
[TemporaryAccessPassMethods ]: Represents a Temporary Access Pass registered to a user for authentication through time-limited passcodes.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[IsUsable ]: The state of the authentication method that indicates whether it's currently usable by the user.
[IsUsableOnce ]: Determines whether the pass is limited to a one-time use.
If true, the pass can be used once; if false, the pass can be used multiple times within the Temporary Access Pass lifetime.
[LifetimeInMinutes ]: The lifetime of the Temporary Access Pass in minutes starting at startDateTime.
Must be between 10 and 43200 inclusive (equivalent to 30 days).
[MethodUsabilityReason ]: Details about the usability state (isUsable).
Reasons can include: EnabledByPolicy, DisabledByPolicy, Expired, NotYetValid, OneTimeUsed.
[StartDateTime ]: The date and time when the Temporary Access Pass becomes available to use and when isUsable is true is enforced.
[TemporaryAccessPass ]: The Temporary Access Pass used to authenticate.
Returned only on creation of a new temporaryAccessPassAuthenticationMethod object; Hidden in subsequent read operations and returned as null with GET.
[WindowsHelloForBusinessMethods ]: Represents the Windows Hello for Business authentication method registered to a user for authentication.
[CreatedDateTime ]: Represents the date and time when an entity was created.
Read-only.
[Id ]: The unique identifier for an entity.
Read-only.
[Device ]: device
[DisplayName ]: The name of the device on which Windows Hello for Business is registered
[KeyStrength ]: authenticationMethodKeyStrength
[AuthorizationInfo ]: authorizationInfo
[(Any) ]: This indicates any property can be added to this object.
[CertificateUserIds ]:
[Birthday ]: The birthday of the user.
The Timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2014, is 2014-01-01T00:00:00Z.
Requires $select to retrieve.
[BusinessPhones ]: The telephone numbers for the user.
NOTE: Although it's a string collection, only one number can be set for this property.
Read-only for users synced from the on-premises directory.
Returned by default.
Supports $filter (eq, not, ge, le, startsWith).
This property is subject to sensitive action restrictions; only specific privileged administrator roles can update it.
[Calendar ]: calendar
[(Any) ]: This indicates any property can be added to this object.
[Id ]: The unique identifier for an entity.
Read-only.
[AllowedOnlineMeetingProviders ]: Represent the online meeting service providers that can be used to create online meetings in this calendar.
The possible values are: unknown, skypeForBusiness, skypeForConsumer, teamsForBusiness.
[CalendarPermissions ]: The permissions of the users with whom the calendar is shared.
[Id ]: The unique identifier for an entity.
Read-only.
[AllowedRoles ]: List of allowed sharing or delegating permission levels for the calendar.
The possible values are: none, freeBusyRead, limitedRead, read, write, delegateWithoutPrivateEventAccess, delegateWithPrivateEventAccess, custom.
[EmailAddress ]: emailAddress
[(Any) ]: This indicates any property can be added to this object.
[Address ]: The email address of the person or entity.
[Name