ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
servicePrincipalLockConfiguration object Specifies whether sensitive properties of a multitenant application should be locked for editing after the application is provisioned in a tenant
web object Specifies settings for a web application
 redirectUris list<string> Redirect URIs for the web application
 implicitGrantSettings object Specifies whether this web application can request tokens using the OAuth 2.0 implicit flow
 enableAccessTokenIssuance boolean Specifies whether this web application can request an access token using the OAuth 2.0 implicit flow
 enableIdTokenIssuance boolean Specifies whether this web application can request an ID token using the OAuth 2.0 implicit flow
 redirectUriSettings list<object> Redirect URI settings for the web application
 homePageUrl string Home page URL of the application
 logoutUrl string Logout URL of the application
appId string Application ID of the application
tokenEncryptionKeyId string Token encryption key ID for the application
passwordCredentials list<object> The collection of password credentials associated with the application
publicClient object Specifies settings for installed clients such as desktop or mobile devices
 redirectUris list<string> Redirect URIs for the public client
requiredResourceAccess list<object> Flattened view of required resource access permissions. Each entry represents a single permission with its parent resource app ID.
 accessId string The unique identifier for the specific permission
 accessType string The type of permission - Role (application) or Scope (delegated)
 resourceAppId string The unique identifier for the resource application
isDeviceOnlyAuthSupported boolean Indicates if device-only authentication is supported
isFallbackPublicClient boolean Indicates if the application is a fallback public client
groupMembershipClaims string Group membership claims for the application
oauth2RequiredPostResponse boolean Specifies whether Microsoft Entra ID allows POST requests as part of OAuth 2.0 token requests instead of only GET requests
samlMetadataUrl string SAML metadata URL of the application
nativeAuthenticationApisEnabled string Specifies whether the Native Authentication APIs are enabled for the application. Possible values are none and all.
tags list<string> Tags associated with the application
certification object Specifies the certification status of the application
addIns list<object> Defines custom behavior that a consuming service can use to call an app in specific contexts
disabledByMicrosoftStatus string Disabled status of the application by Microsoft
displayName string Display name of the application
description string Description of the application
publisherDomain string Publisher domain of the application
uniqueName string Unique name of the application
defaultRedirectUri string Default redirect URI of the application
requestSignatureVerification object Specifies whether this application requires Microsoft Entra ID to verify the signed authentication requests
api object Specifies settings for an application that implements a web API
 knownClientApplications list<string> Known client applications for the API
 requestedAccessTokenVersion number Requested access token version for the API
 oauth2PermissionScopes list<object> The definition of the delegated permissions exposed by the web API represented by this application registration
 preAuthorizedApplications list<object> Lists the client applications that are preauthorized with the specified delegated permissions to access this application's APIs
 acceptMappedClaims boolean Indicates if mapped claims are accepted
deletedDateTime string Date and time when the application was deleted
applicationTemplateId string Template ID of the application
info object Basic profile information of the application such as app's marketing, support, terms of service and privacy statement URLs
 marketingUrl string Marketing URL of the application
 privacyStatementUrl string Privacy statement URL of the application
 supportUrl string Support URL of the application
 termsOfServiceUrl string Terms of service URL of the application
 logoUrl string Logo URL of the application
verifiedPublisher object Specifies the verified publisher of the application
 displayName string Display name of the verified publisher
 verifiedPublisherId string Verified publisher ID
 addedDateTime string Date and time when the publisher was added
spa object Specifies settings for a single-page application, including sign out URLs and redirect URIs for authorization codes and access tokens
 redirectUris list<string> Redirect URIs for the SPA
identifierUris list<string> Identifier URIs of the application
createdByAppId string Unique identifier of the application that created the app registration
appRoles list<object> The collection of roles defined for the application. With app role assignments, these roles can be assigned to users, groups, or service principals associated with other applications
serviceManagementReference string Service management reference for the application
optionalClaims object Application developers can configure optional claims in their Microsoft Entra applications to specify the claims that are sent to their application by the Microsoft security token service
keyCredentials list<object> The collection of key credentials associated with the application
parentalControlSettings object Specifies parental control settings for an application
 countriesBlockedForMinors list<string> Countries blocked for minors
 legalAgeGroupRule string Legal age group rule for the application
id string Unique identifier for the application
isDisabled boolean Specifies whether Microsoft has disabled the registered application
createdDateTime string Date and time when the application was created
notes string Notes associated with the application
signInAudience string Sign-in audience of the application
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
id string Developer-provided unique ID of the connection within the Microsoft Entra tenant
description string Description of the connection displayed in the Microsoft 365 admin center
connectorId string Identifier for the connector used in the external connection
state string Indicates the current state of the connection. Possible values are draft, ready, obsolete, limitExceeded, unknownFutureValue
searchSettings object The settings configuring the search experience for content in this connection, such as the display templates for search results
configuration object Specifies additional application IDs that are allowed to manage the connection and to index content in the connection
 authorizedApps list<string> List of authorized applications for the external connection
 authorizedAppIds list<string> A collection of application IDs for registered Microsoft Entra apps that are allowed to manage the externalConnection and to index content in the externalConnection
name string The display name of the connection to be displayed in the Microsoft 365 admin center
contentCategory string The category of content ingested by this connection. Possible values are uncategorized, knowledgeBase, wikis, fileRepository, qna, crm, dashboard, people, media, email, messaging, meetingTranscripts, taskManagement, learningManagement, unknownFutureValue
activitySettings object Collects configurable settings related to activities involving connector content
 urlToItemResolvers list<object> Specifies configurations to identify an externalItem based on a shared URL
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
PolicyRulesMetaData string Metadata associated with the policy rules, containing additional configuration information. e.g., ''
Locations string Consolidated string representation of all locations where the policy applies. e.g., ''
Workload string Comma-separated list of Microsoft 365 workloads where this policy applies. Possible values: Exchange, SharePoint, OneDriveForBusiness, Skype, ModernGroup, Applications. e.g., Exchange, SharePoint, OneDriveForBusiness, Skype, ModernGroup, Applications
ExternalIdentity string External identity reference for the policy, used for cross-system identification. e.g., ''
PolicyRBACScopes list<string> Administrative unit GUIDs (from Microsoft Entra ID) that define the RBAC scope for policy administration. Limits which admins can manage this policy. e.g., []
UPELabelRules list<string> Unified Policy Engine label rules. Distinguished names of label policy tracking rules in Exchange configuration. e.g., ['FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/tenant.onmicrosoft.com/Configuration/lptr-52ffc042-c8f7-4884-afa0-bd03f4dc4e88']
SharePointLocation list<string> SharePoint sites included in the policy scope. When specified, the policy applies only to these SharePoint locations. e.g., []
ModernGroupLocation list<string> Microsoft 365 Groups included in the policy scope. Identified by primary SMTP address. e.g., []
ModernGroupLocationException list<string> Microsoft 365 Groups excluded from the policy scope. e.g., []
TeamsAdaptiveScopesException list<string> Adaptive scopes excluded from Teams policy scope. e.g., []
ErrorMetadata object Metadata about any errors that occurred during policy distribution or validation.
LastStatusUpdateTime string Timestamp of the last status update for policy distribution.
Guid string GUID uniquely identifying the policy object. e.g., 1c77340e-0b71-4573-9931-0393eb6dca53
ExchangeAdaptiveScopesException list<string> Adaptive scopes excluded from Exchange policy scope. e.g., []
PolicyConstraints string JSON string containing policy constraints including administrative unit restrictions. e.g., {"AdministrativeUnit":[]}
LastModifiedBy string Identity of the user or service that last modified the policy. e.g., ''
ExchangeObjectId string GUID of the policy object in Exchange Online. e.g., 1c77340e-0b71-4573-9931-0393eb6dca53
ObjectState string Current state of the policy object. 'Changed' indicates pending modifications, 'Unchanged' means synced. e.g., Changed
OneDriveLocationException list<string> OneDrive for Business locations excluded from the policy scope. e.g., []
CreatedBy string Identity of the user or service that created the policy. e.g., ''
SkypeLocation list<string> Skype for Business locations included in the policy scope. e.g., []
SkypeLocationException list<string> Skype for Business locations excluded from the policy scope. e.g., []
OneDriveAdaptiveScopesException list<string> Adaptive scopes excluded from OneDrive policy scope. e.g., []
Enabled boolean Whether the policy is enabled and actively enforcing labels. When false, the policy exists but doesn't apply labels. e.g., True
DistributionResults object Detailed results of policy distribution to each location/workload, including any errors.
ModificationTimeUtc string UTC timestamp when the policy was last modified. e.g., 2025-09-16T04:47:27.263
Identity string Distinguished name uniquely identifying the policy in Exchange configuration. Can be used with Get-LabelPolicy -Identity parameter. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration/Global sensitivity label policy
OrganizationalUnitRoot string Root organizational unit path for the tenant in Exchange configuration. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com
DistributionSyncStatus string Synchronization status of the policy distribution. Indicates whether the policy has been successfully synced to all target locations. e.g., Success
WhenCreatedUTC string UTC timestamp when the policy was created in ISO 8601 format. e.g., 2025-09-16T04:47:27Z
OrganizationId string Full organization identifier including both the OU root and configuration container path. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com - FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration
ExchangeLocation list<object> Exchange mailboxes included in the policy scope. Contains location objects with display name, type, status, and workload information.
 Type object Type of the Exchange location (e.g., Tenant, User, Group).
 value number Numeric value representing the location type. e.g., 1
 Value string String representation of the location type. e.g., Tenant
 SourceEntryType object The entry type of the source.
 value number Numeric value representing the source entry type. e.g., 0
 Value string String representation of the source entry type. e.g., Unknown
 SchemaVersion number Schema version of the location entry format. e.g., 2
 ImmutableIdentity string Immutable identity of the Exchange location that doesn't change even if the display name changes. e.g., All
 Status object Distribution status of the policy to this location.
 value number Numeric value representing the status. e.g., 2
 Value string String representation of the status (e.g., Success, Pending, Failed). e.g., Success
 Workload object The Microsoft 365 workload this location applies to.
 value number Numeric value representing the workload. e.g., 1
 Value string String representation of the workload (e.g., Exchange, SharePoint, OneDriveForBusiness). e.g., Exchange
 SourceType string The source type of the location entry.
 SourceTypeDisplayName string Display name of the source type.
 SourceProvider object The provider source of the location.
 value number Numeric value representing the source provider. e.g., 0
 Value string String representation of the source provider. e.g., Unknown
 Resources list<string> Additional resources associated with this location.
 DisplayName string Display name of the Exchange location. 'All' indicates all mailboxes in the tenant. e.g., All
 Name string Name identifier of the Exchange location. e.g., All
ExchangeLocationException list<string> Exchange mailboxes excluded from the policy scope when ExchangeLocation is set to 'All'. e.g., []
ObjectVersion string GUID representing the current version of the policy object. Changes when the policy is modified. e.g., 036c8398-99db-4088-1631-08ddf4dc22ef
Name string The unique display name of the sensitivity label policy. Maximum 64 characters. e.g., Global sensitivity label policy
ForceValidate boolean Whether to force validation of the policy configuration. When true, validates policy even if cached validation exists. e.g., False
ReadOnly boolean Whether the policy is read-only and cannot be modified. System-managed policies may be read-only. e.g., False
TeamsAdaptiveScopes list<string> Adaptive scopes for Microsoft Teams that dynamically define policy scope. e.g., []
Mode string Policy enforcement mode. 'Enforce' means the policy actively applies labels. Other modes may include 'Test' for simulation. e.g., Enforce
id string Internal unique identifier combining entity type, SharePoint admin URL, Azure tenant ID, and policy identity. e.g., LabelPolicy-https://spmdev01-admin.sharepoint.com-527424f5-d4df-43a4-af03-06a4501696d1-FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration/Global sensitivity label policy
Labels list<string> List of sensitivity label GUIDs associated with this policy. These are the labels that users assigned to this policy can apply to content. e.g., ['defa4170-0d19-0005-0004-bc88714345d2', 'defa4170-0d19-0005-0008-bc88714345d2', 'defa4170-0d19-0005-0002-bc88714345d2']
ScopedLabels list<string> List of sensitivity label GUIDs that are scoped (restricted) to specific users, groups, or locations within this policy. e.g., ['defa4170-0d19-0005-0001-bc88714345d2', 'defa4170-0d19-0005-0008-bc88714345d2']
SharePointAdaptiveScopesException list<string> Adaptive scopes excluded from SharePoint policy scope. e.g., []
EndpointDlpAdaptiveScopesException list<string> Adaptive scopes excluded from Endpoint DLP policy scope.
UserAdministrativeUnitMembershipMap object Mapping of users to their administrative unit memberships for scoped policy administration.
Priority number Policy priority order. Lower numbers indicate lower priority. When settings conflict between policies, higher priority (higher number) wins. e.g., 0
ObjectCategory string LDAP object category for the policy in Exchange directory.
WhenCreated string Local timestamp when the policy was created, with timezone offset. e.g., 2025-09-16T04:47:27+00:00
LabelType string The type of sensitivity label policy. Indicates the policy classification type. e.g., PublishedSensitivityLabel
Comment string Administrative comment or description for the policy explaining its purpose. e.g., Default sensitivity label policy for all users and groups.
PolicySettingsBlob string XML blob containing detailed policy settings including default label IDs, mandatory labeling flags for different workloads (teamwork, Outlook, Power BI), and downgrade justification requirements. e.g., <settings><setting key="defaultlabelid" value="defa4170-0d19-0005-0004-bc88714345d2" /><setting key="teamworkmandatory" value="false" /></settings>
OneDriveLocation list<string> OneDrive for Business locations included in the policy scope. e.g., []
SharePointAdaptiveScopes list<string> Adaptive scopes for SharePoint that dynamically define policy scope based on site attributes. e.g., []
DistributionStatus string Current distribution status of the policy across Microsoft 365 services. Values: Pending, Success, Failed. e.g., Pending
Id string Unique identifier for the policy. Same as Identity for label policies. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration/Global sensitivity label policy
IsValid boolean Whether the policy configuration is valid and can be enforced. e.g., True
OneDriveAdaptiveScopes list<string> Adaptive scopes for OneDrive that dynamically define policy scope based on user attributes. e.g., []
CreationTimeUtc string UTC timestamp when the policy was created. e.g., 2025-09-16T04:47:27.263
ExchangeVersion string Exchange version that the policy object was created with. Indicates schema compatibility. e.g., 0.20 (15.0.0.0)
DistinguishedName string Full LDAP-style distinguished name of the policy object in Exchange configuration. e.g., CN=Global sensitivity label policy,CN=Configuration,CN=spmdev01.onmicrosoft.com,OU=Microsoft Exchange Hosted Organizations,DC=FFO,DC=extest,DC=microsoft,DC=com
Settings list<string> Policy settings as key-value pairs controlling label behavior. Includes default labels, mandatory labeling options, and downgrade justification requirements for different workloads (Outlook, Teams, Power BI). e.g., ['[defaultlabelid, defa4170-0d19-0005-0004-bc88714345d2]', '[teamworkmandatory, false]', '[disablemandatoryinoutlook, true]', '[requiredowngradejustification, true]', '[mandatory, false]', '[powerbimandatory, false]']
SharePointLocationException list<string> SharePoint sites excluded from the policy scope when SharePointLocation is set to 'All'. e.g., []
PublicFolderLocation list<string> Public folders included in the policy scope. e.g., []
EndpointDlpAdaptiveScopes list<string> Adaptive scopes for Endpoint DLP (Data Loss Prevention) policies.
GlobalListType string Indicates whether this is a global list policy type. 'None' means it's not a global list. e.g., None
ObjectClass list<string> LDAP object classes for the policy. 'msExchUnifiedPolicy' indicates a Microsoft Purview unified policy. e.g., ['msExchUnifiedPolicy']
ExchangeAdaptiveScopes list<string> Adaptive scopes for Exchange that dynamically define policy scope based on user/group attributes. e.g., []
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ns_id string Stable resource identifier -- "LabelPolicySetting_" + tenant-ID suffix of the Microsoft-generated id hash. Used as ResID to avoid churn from the volatile 64-char prefix that Microsoft regenerates on policy changes.
id string Microsoft-generated 96-char hash identifier for the policy. The last 32 chars are the tenant ID (stable); the 64-char prefix is volatile and may change when policies are modified.
moreInfoUrl string Exposes the more information URL that can be configured by the administrator
isMandatory boolean Exposes whether mandatory labeling is enabled
isDowngradeJustificationRequired boolean Exposes whether justification input is required on label downgrade
defaultLabelId string The unique identifier of the default sensitivity label applied to content when no label is selected by the user. References the defaultLabel relationship
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
OrgAssetType number The type of organizational asset. 1 indicates ImageDocumentLibrary, 2 indicates OfficeTemplateLibrary
TypeId string GUID identifying the object type schema
id string Internal unique identifier combining entity type, SharePoint admin URL, Azure tenant ID, and library identity
FileType string The default file type associated with the library (e.g., docx, png, jpg)
ListId string The unique identifier (GUID) of the SharePoint list/library
ThumbnailUrl object URL information for the library thumbnail image
 DecodedUrl string The relative path to the thumbnail image file
 TypeId string GUID identifying the URL type
UniqueId string The unique identifier (GUID) for this organizational assets library entry
DisplayName string The display name of the organizational assets library
LibraryUrl object URL information for the organizational assets library location
 DecodedUrl string The server relative URL of the document library flagged as organizational asset library (e.g., sites/branding/logos)
 TypeId string GUID identifying the URL type
ATTRIBUTE TYPE REFERS TO DESCRIPTION
color string The color that the UI should display for the label, if configured
parent object Parent sensitivity label, if any. Returns the parent label when this label is a sublabel. Null if there is no parent
 name string The plaintext name of the label
 description string The admin-defined description for the label
 sensitivity number The sensitivity value of the label, where lower is less sensitive
 isAppliable boolean Indicates whether the label can be applied to content. False if the label is a parent with child labels
 contentFormats list<string> Returns the supported content formats for the label
 hasProtection boolean Indicates whether the label has protection actions configured
 color string The color that the UI should display for the label, if configured
 tooltip string The tooltip that should be displayed for the label in a UI
 isActive boolean Indicates whether the label is active or not
 id string The label ID is a globally unique identifier (GUID)
toolTipDSG string The tooltip from the DSG endpoint (may differ from informationProtection tooltip)
isEndpointProtectionEnabled boolean Indicates whether endpoint data loss prevention is enabled for the label
autoTooltip string The tooltip shown when the label is automatically applied
isSmimeEncryptEnabled boolean Indicates whether S/MIME encryption is enabled for the label
assignedPolicies list<object> Label policies that include this label
isDefault boolean Indicates whether this is the default label
labelActions list<object> Actions associated with the label (e.g., encryption, watermarking)
customSettings list<object> Custom key-value settings for the label
name string The plaintext name of the label
description string The admin-defined description for the label
isActive boolean Indicates whether the label is active or not. Active labels should be hidden or disabled in the UI
isAppliable boolean Indicates whether the label can be applied to content. False if the label is a parent with child labels
tooltip string The tooltip that should be displayed for the label in a UI
hasProtection boolean Indicates whether the label has protection actions (such as encryption or do not forward) configured
priority number The priority of the label. Lower number indicates higher priority
actionSource string How the label action is applied (manual, automatic, recommended, default)
locale string The locale setting for the label
id string The label ID is a globally unique identifier (GUID)
isEnabled boolean Indicates whether the label is currently enabled for use
isScopedToUser boolean Indicates whether the label is scoped to a specific user via label policy
applicationMode string The application mode for the label
contentFormats list<string> Returns the supported content formats for the label (e.g., file, email, teamwork)
displayName string The display name of the label from the DSG endpoint
sublabels list<object> Sublabels nested under this parent label (from DSG endpoint)
rights object Rights management settings for the label
sensitivity number The sensitivity value of the label, where lower is less sensitive
applicableTo string Content types the label can be applied to (comma-separated values such as email, file, teamwork, site, unifiedGroup)
autoLabeling object The auto-labeling configuration for the label, specifying conditions that trigger automatic label application
isSmimeSignEnabled boolean Indicates whether S/MIME signing is enabled for the label
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
id string Unique identifier combining the resource type, SharePoint admin URL, and tenant ID
Value list<string> List of SharePoint site URLs that Copilot for M365 is allowed to search when the tenant is in restricted search mode
ATTRIBUTE TYPE REFERS TO DESCRIPTION
Value number The restricted search mode setting for the tenant. 0 = Disabled (Copilot can search all SharePoint content), 1 = Enabled (Copilot can only search content from sites in the allowed list)
id string Unique identifier combining the resource type, SharePoint admin URL, and tenant ID
ATTRIBUTE TYPE REFERS TO DESCRIPTION
Url string The URL of the SharePoint site.
Title string The title of the SharePoint site.
RestrictContentOrgWideSearch boolean Indicates whether the site content is restricted from organization-wide search. When true, the site content is excluded from org-wide search results.
id string Unique identifier combining the resource type, SharePoint admin URL, tenant ID, and site URL