ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
appRoles list<object> The collection of roles defined for the application. With app role assignments, these roles can be assigned to users, groups, or service principals associated with other applications
requiredResourceAccess list<object> Flattened view of required resource access permissions. Each entry represents a single permission with its parent resource app ID.
 resourceAppId string The unique identifier for the resource application
 accessId string The unique identifier for the specific permission
 accessType string The type of permission - Role (application) or Scope (delegated)
id string Unique identifier for the application
nativeAuthenticationApisEnabled string Specifies whether the Native Authentication APIs are enabled for the application. Possible values are none and all.
notes string Notes associated with the application
publisherDomain string Publisher domain of the application
tokenEncryptionKeyId string Token encryption key ID for the application
verifiedPublisher object Specifies the verified publisher of the application
 displayName string Display name of the verified publisher
 verifiedPublisherId string Verified publisher ID
 addedDateTime string Date and time when the publisher was added
identifierUris list<string> Identifier URIs of the application
appId string Application ID of the application
isDisabled boolean Specifies whether Microsoft has disabled the registered application
createdDateTime string Date and time when the application was created
groupMembershipClaims string Group membership claims for the application
passwordCredentials list<object> The collection of password credentials associated with the application
web object Specifies settings for a web application
 homePageUrl string Home page URL of the application
 logoutUrl string Logout URL of the application
 redirectUris list<string> Redirect URIs for the web application
 implicitGrantSettings object Specifies whether this web application can request tokens using the OAuth 2.0 implicit flow
 enableIdTokenIssuance boolean Specifies whether this web application can request an ID token using the OAuth 2.0 implicit flow
 enableAccessTokenIssuance boolean Specifies whether this web application can request an access token using the OAuth 2.0 implicit flow
 redirectUriSettings list<object> Redirect URI settings for the web application
servicePrincipalLockConfiguration object Specifies whether sensitive properties of a multitenant application should be locked for editing after the application is provisioned in a tenant
api object Specifies settings for an application that implements a web API
 acceptMappedClaims boolean Indicates if mapped claims are accepted
 knownClientApplications list<string> Known client applications for the API
 requestedAccessTokenVersion number Requested access token version for the API
 oauth2PermissionScopes list<object> The definition of the delegated permissions exposed by the web API represented by this application registration
 preAuthorizedApplications list<object> Lists the client applications that are preauthorized with the specified delegated permissions to access this application's APIs
info object Basic profile information of the application such as app's marketing, support, terms of service and privacy statement URLs
 logoUrl string Logo URL of the application
 marketingUrl string Marketing URL of the application
 privacyStatementUrl string Privacy statement URL of the application
 supportUrl string Support URL of the application
 termsOfServiceUrl string Terms of service URL of the application
publicClient object Specifies settings for installed clients such as desktop or mobile devices
 redirectUris list<string> Redirect URIs for the public client
spa object Specifies settings for a single-page application, including sign out URLs and redirect URIs for authorization codes and access tokens
 redirectUris list<string> Redirect URIs for the SPA
applicationTemplateId string Template ID of the application
createdByAppId string Unique identifier of the application that created the app registration
displayName string Display name of the application
serviceManagementReference string Service management reference for the application
tags list<string> Tags associated with the application
parentalControlSettings object Specifies parental control settings for an application
 countriesBlockedForMinors list<string> Countries blocked for minors
 legalAgeGroupRule string Legal age group rule for the application
disabledByMicrosoftStatus string Disabled status of the application by Microsoft
isFallbackPublicClient boolean Indicates if the application is a fallback public client
oauth2RequiredPostResponse boolean Specifies whether Microsoft Entra ID allows POST requests as part of OAuth 2.0 token requests instead of only GET requests
signInAudience string Sign-in audience of the application
certification object Specifies the certification status of the application
optionalClaims object Application developers can configure optional claims in their Microsoft Entra applications to specify the claims that are sent to their application by the Microsoft security token service
requestSignatureVerification object Specifies whether this application requires Microsoft Entra ID to verify the signed authentication requests
addIns list<object> Defines custom behavior that a consuming service can use to call an app in specific contexts
deletedDateTime string Date and time when the application was deleted
isDeviceOnlyAuthSupported boolean Indicates if device-only authentication is supported
uniqueName string Unique name of the application
samlMetadataUrl string SAML metadata URL of the application
defaultRedirectUri string Default redirect URI of the application
keyCredentials list<object> The collection of key credentials associated with the application
description string Description of the application
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
activitySettings object Collects configurable settings related to activities involving connector content
 urlToItemResolvers list<object> Specifies configurations to identify an externalItem based on a shared URL
description string Description of the connection displayed in the Microsoft 365 admin center
connectorId string Identifier for the connector used in the external connection
contentCategory string The category of content ingested by this connection. Possible values are uncategorized, knowledgeBase, wikis, fileRepository, qna, crm, dashboard, people, media, email, messaging, meetingTranscripts, taskManagement, learningManagement, unknownFutureValue
state string Indicates the current state of the connection. Possible values are draft, ready, obsolete, limitExceeded, unknownFutureValue
configuration object Specifies additional application IDs that are allowed to manage the connection and to index content in the connection
 authorizedApps list<string> List of authorized applications for the external connection
 authorizedAppIds list<string> A collection of application IDs for registered Microsoft Entra apps that are allowed to manage the externalConnection and to index content in the externalConnection
id string Developer-provided unique ID of the connection within the Microsoft Entra tenant
name string The display name of the connection to be displayed in the Microsoft 365 admin center
searchSettings object The settings configuring the search experience for content in this connection, such as the display templates for search results
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ObjectState string Current state of the policy object. 'Changed' indicates pending modifications, 'Unchanged' means synced. e.g., Changed
Workload string Comma-separated list of Microsoft 365 workloads where this policy applies. Possible values: Exchange, SharePoint, OneDriveForBusiness, Skype, ModernGroup, Applications. e.g., Exchange, SharePoint, OneDriveForBusiness, Skype, ModernGroup, Applications
Labels list<string> List of sensitivity label GUIDs associated with this policy. These are the labels that users assigned to this policy can apply to content. e.g., ['defa4170-0d19-0005-0004-bc88714345d2', 'defa4170-0d19-0005-0008-bc88714345d2', 'defa4170-0d19-0005-0002-bc88714345d2']
ScopedLabels list<string> List of sensitivity label GUIDs that are scoped (restricted) to specific users, groups, or locations within this policy. e.g., ['defa4170-0d19-0005-0001-bc88714345d2', 'defa4170-0d19-0005-0008-bc88714345d2']
OneDriveLocationException list<string> OneDrive for Business locations excluded from the policy scope. e.g., []
ExchangeAdaptiveScopesException list<string> Adaptive scopes excluded from Exchange policy scope. e.g., []
CreationTimeUtc string UTC timestamp when the policy was created. e.g., 2025-09-16T04:47:27.263
Identity string Distinguished name uniquely identifying the policy in Exchange configuration. Can be used with Get-LabelPolicy -Identity parameter. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration/Global sensitivity label policy
ObjectClass list<string> LDAP object classes for the policy. 'msExchUnifiedPolicy' indicates a Microsoft Purview unified policy. e.g., ['msExchUnifiedPolicy']
GlobalListType string Indicates whether this is a global list policy type. 'None' means it's not a global list. e.g., None
DistributionStatus string Current distribution status of the policy across Microsoft 365 services. Values: Pending, Success, Failed. e.g., Pending
id string Internal unique identifier combining entity type, SharePoint admin URL, Azure tenant ID, and policy identity. e.g., LabelPolicy-https://spmdev01-admin.sharepoint.com-527424f5-d4df-43a4-af03-06a4501696d1-FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration/Global sensitivity label policy
UPELabelRules list<string> Unified Policy Engine label rules. Distinguished names of label policy tracking rules in Exchange configuration. e.g., ['FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/tenant.onmicrosoft.com/Configuration/lptr-52ffc042-c8f7-4884-afa0-bd03f4dc4e88']
SharePointLocation list<string> SharePoint sites included in the policy scope. When specified, the policy applies only to these SharePoint locations. e.g., []
TeamsAdaptiveScopes list<string> Adaptive scopes for Microsoft Teams that dynamically define policy scope. e.g., []
TeamsAdaptiveScopesException list<string> Adaptive scopes excluded from Teams policy scope. e.g., []
UserAdministrativeUnitMembershipMap object Mapping of users to their administrative unit memberships for scoped policy administration.
ForceValidate boolean Whether to force validation of the policy configuration. When true, validates policy even if cached validation exists. e.g., False
DistributionResults object Detailed results of policy distribution to each location/workload, including any errors.
PolicyRBACScopes list<string> Administrative unit GUIDs (from Microsoft Entra ID) that define the RBAC scope for policy administration. Limits which admins can manage this policy. e.g., []
SkypeLocation list<string> Skype for Business locations included in the policy scope. e.g., []
Priority number Policy priority order. Lower numbers indicate lower priority. When settings conflict between policies, higher priority (higher number) wins. e.g., 0
DistinguishedName string Full LDAP-style distinguished name of the policy object in Exchange configuration. e.g., CN=Global sensitivity label policy,CN=Configuration,CN=spmdev01.onmicrosoft.com,OU=Microsoft Exchange Hosted Organizations,DC=FFO,DC=extest,DC=microsoft,DC=com
ExchangeLocationException list<string> Exchange mailboxes excluded from the policy scope when ExchangeLocation is set to 'All'. e.g., []
ModernGroupLocation list<string> Microsoft 365 Groups included in the policy scope. Identified by primary SMTP address. e.g., []
ErrorMetadata object Metadata about any errors that occurred during policy distribution or validation.
Comment string Administrative comment or description for the policy explaining its purpose. e.g., Default sensitivity label policy for all users and groups.
ExchangeVersion string Exchange version that the policy object was created with. Indicates schema compatibility. e.g., 0.20 (15.0.0.0)
WhenCreated string Local timestamp when the policy was created, with timezone offset. e.g., 2025-09-16T04:47:27+00:00
PublicFolderLocation list<string> Public folders included in the policy scope. e.g., []
Locations string Consolidated string representation of all locations where the policy applies. e.g., ''
IsValid boolean Whether the policy configuration is valid and can be enforced. e.g., True
ObjectCategory string LDAP object category for the policy in Exchange directory.
WhenCreatedUTC string UTC timestamp when the policy was created in ISO 8601 format. e.g., 2025-09-16T04:47:27Z
OrganizationalUnitRoot string Root organizational unit path for the tenant in Exchange configuration. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com
CreatedBy string Identity of the user or service that created the policy. e.g., ''
Guid string GUID uniquely identifying the policy object. e.g., 1c77340e-0b71-4573-9931-0393eb6dca53
Settings list<string> Policy settings as key-value pairs controlling label behavior. Includes default labels, mandatory labeling options, and downgrade justification requirements for different workloads (Outlook, Teams, Power BI). e.g., ['[defaultlabelid, defa4170-0d19-0005-0004-bc88714345d2]', '[teamworkmandatory, false]', '[disablemandatoryinoutlook, true]', '[requiredowngradejustification, true]', '[mandatory, false]', '[powerbimandatory, false]']
ExchangeLocation list<object> Exchange mailboxes included in the policy scope. Contains location objects with display name, type, status, and workload information.
 ImmutableIdentity string Immutable identity of the Exchange location that doesn't change even if the display name changes. e.g., All
 Type object Type of the Exchange location (e.g., Tenant, User, Group).
 value number Numeric value representing the location type. e.g., 1
 Value string String representation of the location type. e.g., Tenant
 Status object Distribution status of the policy to this location.
 value number Numeric value representing the status. e.g., 2
 Value string String representation of the status (e.g., Success, Pending, Failed). e.g., Success
 Workload object The Microsoft 365 workload this location applies to.
 value number Numeric value representing the workload. e.g., 1
 Value string String representation of the workload (e.g., Exchange, SharePoint, OneDriveForBusiness). e.g., Exchange
 SourceType string The source type of the location entry.
 SourceTypeDisplayName string Display name of the source type.
 SchemaVersion number Schema version of the location entry format. e.g., 2
 DisplayName string Display name of the Exchange location. 'All' indicates all mailboxes in the tenant. e.g., All
 SourceProvider object The provider source of the location.
 value number Numeric value representing the source provider. e.g., 0
 Value string String representation of the source provider. e.g., Unknown
 SourceEntryType object The entry type of the source.
 value number Numeric value representing the source entry type. e.g., 0
 Value string String representation of the source entry type. e.g., Unknown
 Resources list<string> Additional resources associated with this location.
 Name string Name identifier of the Exchange location. e.g., All
OneDriveLocation list<string> OneDrive for Business locations included in the policy scope. e.g., []
OneDriveAdaptiveScopesException list<string> Adaptive scopes excluded from OneDrive policy scope. e.g., []
ReadOnly boolean Whether the policy is read-only and cannot be modified. System-managed policies may be read-only. e.g., False
SkypeLocationException list<string> Skype for Business locations excluded from the policy scope. e.g., []
ModernGroupLocationException list<string> Microsoft 365 Groups excluded from the policy scope. e.g., []
Enabled boolean Whether the policy is enabled and actively enforcing labels. When false, the policy exists but doesn't apply labels. e.g., True
OrganizationId string Full organization identifier including both the OU root and configuration container path. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com - FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration
ExchangeAdaptiveScopes list<string> Adaptive scopes for Exchange that dynamically define policy scope based on user/group attributes. e.g., []
EndpointDlpAdaptiveScopes list<string> Adaptive scopes for Endpoint DLP (Data Loss Prevention) policies.
LastModifiedBy string Identity of the user or service that last modified the policy. e.g., ''
Mode string Policy enforcement mode. 'Enforce' means the policy actively applies labels. Other modes may include 'Test' for simulation. e.g., Enforce
LastStatusUpdateTime string Timestamp of the last status update for policy distribution.
ExchangeObjectId string GUID of the policy object in Exchange Online. e.g., 1c77340e-0b71-4573-9931-0393eb6dca53
LabelType string The type of sensitivity label policy. Indicates the policy classification type. e.g., PublishedSensitivityLabel
ExternalIdentity string External identity reference for the policy, used for cross-system identification. e.g., ''
DistributionSyncStatus string Synchronization status of the policy distribution. Indicates whether the policy has been successfully synced to all target locations. e.g., Success
ModificationTimeUtc string UTC timestamp when the policy was last modified. e.g., 2025-09-16T04:47:27.263
Id string Unique identifier for the policy. Same as Identity for label policies. e.g., FFO.extest.microsoft.com/Microsoft Exchange Hosted Organizations/spmdev01.onmicrosoft.com/Configuration/Global sensitivity label policy
PolicySettingsBlob string XML blob containing detailed policy settings including default label IDs, mandatory labeling flags for different workloads (teamwork, Outlook, Power BI), and downgrade justification requirements. e.g., <settings><setting key="defaultlabelid" value="defa4170-0d19-0005-0004-bc88714345d2" /><setting key="teamworkmandatory" value="false" /></settings>
SharePointLocationException list<string> SharePoint sites excluded from the policy scope when SharePointLocation is set to 'All'. e.g., []
SharePointAdaptiveScopes list<string> Adaptive scopes for SharePoint that dynamically define policy scope based on site attributes. e.g., []
OneDriveAdaptiveScopes list<string> Adaptive scopes for OneDrive that dynamically define policy scope based on user attributes. e.g., []
PolicyRulesMetaData string Metadata associated with the policy rules, containing additional configuration information. e.g., ''
SharePointAdaptiveScopesException list<string> Adaptive scopes excluded from SharePoint policy scope. e.g., []
EndpointDlpAdaptiveScopesException list<string> Adaptive scopes excluded from Endpoint DLP policy scope.
PolicyConstraints string JSON string containing policy constraints including administrative unit restrictions. e.g., {"AdministrativeUnit":[]}
ObjectVersion string GUID representing the current version of the policy object. Changes when the policy is modified. e.g., 036c8398-99db-4088-1631-08ddf4dc22ef
Name string The unique display name of the sensitivity label policy. Maximum 64 characters. e.g., Global sensitivity label policy
ATTRIBUTE TYPE REFERS TO DESCRIPTION
moreInfoUrl string Exposes the more information URL that can be configured by the administrator
isMandatory boolean Exposes whether mandatory labeling is enabled
isDowngradeJustificationRequired boolean Exposes whether justification input is required on label downgrade
defaultLabelId string The unique identifier of the default sensitivity label applied to content when no label is selected by the user. References the defaultLabel relationship
id string Unique identifier for the policy
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
id string Internal unique identifier combining entity type, SharePoint admin URL, Azure tenant ID, and library identity
DisplayName string The display name of the organizational assets library
LibraryUrl object URL information for the organizational assets library location
 DecodedUrl string The server relative URL of the document library flagged as organizational asset library (e.g., sites/branding/logos)
 TypeId string GUID identifying the URL type
OrgAssetType number The type of organizational asset. 1 indicates ImageDocumentLibrary, 2 indicates OfficeTemplateLibrary
UniqueId string The unique identifier (GUID) for this organizational assets library entry
FileType string The default file type associated with the library (e.g., docx, png, jpg)
ListId string The unique identifier (GUID) of the SharePoint list/library
ThumbnailUrl object URL information for the library thumbnail image
 DecodedUrl string The relative path to the thumbnail image file
 TypeId string GUID identifying the URL type
TypeId string GUID identifying the object type schema
ATTRIBUTE TYPE REFERS TO DESCRIPTION
isActive boolean Indicates whether the label is active or not. Active labels should be hidden or disabled in the UI
autoTooltip string The tooltip shown when the label is automatically applied
labelActions list<object> Actions associated with the label (e.g., encryption, watermarking)
autoLabeling object The auto-labeling configuration for the label, specifying conditions that trigger automatic label application
sensitivity number The sensitivity value of the label, where lower is less sensitive
toolTipDSG string The tooltip from the DSG endpoint (may differ from informationProtection tooltip)
description string The admin-defined description for the label
tooltip string The tooltip that should be displayed for the label in a UI
parent object Parent sensitivity label, if any. Returns the parent label when this label is a sublabel. Null if there is no parent
 isAppliable boolean Indicates whether the label can be applied to content. False if the label is a parent with child labels
 contentFormats list<string> Returns the supported content formats for the label
 hasProtection boolean Indicates whether the label has protection actions configured
 id string The label ID is a globally unique identifier (GUID)
 name string The plaintext name of the label
 description string The admin-defined description for the label
 color string The color that the UI should display for the label, if configured
 sensitivity number The sensitivity value of the label, where lower is less sensitive
 tooltip string The tooltip that should be displayed for the label in a UI
 isActive boolean Indicates whether the label is active or not
applicationMode string The application mode for the label
customSettings list<object> Custom key-value settings for the label
rights object Rights management settings for the label
applicableTo string Content types the label can be applied to (comma-separated values such as email, file, teamwork, site, unifiedGroup)
isSmimeSignEnabled boolean Indicates whether S/MIME signing is enabled for the label
isAppliable boolean Indicates whether the label can be applied to content. False if the label is a parent with child labels
isEndpointProtectionEnabled boolean Indicates whether endpoint data loss prevention is enabled for the label
priority number The priority of the label. Lower number indicates higher priority
locale string The locale setting for the label
sublabels list<object> Sublabels nested under this parent label (from DSG endpoint)
color string The color that the UI should display for the label, if configured
contentFormats list<string> Returns the supported content formats for the label (e.g., file, email, teamwork)
hasProtection boolean Indicates whether the label has protection actions (such as encryption or do not forward) configured
displayName string The display name of the label from the DSG endpoint
actionSource string How the label action is applied (manual, automatic, recommended, default)
assignedPolicies list<object> Label policies that include this label
name string The plaintext name of the label
isEnabled boolean Indicates whether the label is currently enabled for use
isDefault boolean Indicates whether this is the default label
id string The label ID is a globally unique identifier (GUID)
isScopedToUser boolean Indicates whether the label is scoped to a specific user via label policy
isSmimeEncryptEnabled boolean Indicates whether S/MIME encryption is enabled for the label
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
ATTRIBUTE TYPE REFERS TO DESCRIPTION
Value list<string> List of SharePoint site URLs that Copilot for M365 is allowed to search when the tenant is in restricted search mode
id string Unique identifier combining the resource type, SharePoint admin URL, and tenant ID
ATTRIBUTE TYPE REFERS TO DESCRIPTION
Value number The restricted search mode setting for the tenant. 0 = Disabled (Copilot can search all SharePoint content), 1 = Enabled (Copilot can only search content from sites in the allowed list)
id string Unique identifier combining the resource type, SharePoint admin URL, and tenant ID
ATTRIBUTE TYPE REFERS TO DESCRIPTION
Url string The URL of the SharePoint site.
Title string The title of the SharePoint site.
RestrictContentOrgWideSearch boolean Indicates whether the site content is restricted from organization-wide search. When true, the site content is excluded from org-wide search results.
id string Unique identifier combining the resource type, SharePoint admin URL, tenant ID, and site URL