Skip to main content

owners

Creates, updates, deletes, gets or lists an owners resource.

Overview

Nameowners
TypeResource
Identra_id.service_principals.owners

Fields

The following fields are returned by SELECT queries:

Retrieved collection

NameDatatypeDescription
idstringThe unique identifier for an entity. Read-only.
deletedDateTimestring (date-time)Date and time when this object was deleted. Always null when the object hasn't been deleted. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$)

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectservice_principal_idConsistencyLevelDirectory objects that are owners of this servicePrincipal. The owners are a set of nonadmin users or servicePrincipals who are allowed to modify this object. Supports $expand, $filter (/$count eq 0, /$count ne 0, /$count eq 1, /$count ne 1), and $select nested in $expand.
add_refinsertservice_principal_idUse this API to add an owner for the servicePrincipal. Service principal owners can be users, the service principal itself, or other service principals.
remove_refdeleteservice_principal_id, directory_object_idIf-MatchRemove an owner from a servicePrincipal object. As a recommended best practice, service principals should have at least two owners.
remove_ref_2deleteservice_principal_idIf-MatchRemove an owner from a servicePrincipal object. As a recommended best practice, service principals should have at least two owners.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
directory_object_idstringThe unique identifier of directoryObject
service_principal_idstringThe unique identifier of servicePrincipal
ConsistencyLevelstringIndicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries
If-MatchstringETag

SELECT examples

Directory objects that are owners of this servicePrincipal. The owners are a set of nonadmin users or servicePrincipals who are allowed to modify this object. Supports $expand, $filter (/$count eq 0, /$count ne 0, /$count eq 1, /$count ne 1), and $select nested in $expand.

SELECT
id,
deletedDateTime
FROM entra_id.service_principals.owners
WHERE service_principal_id = '{{ service_principal_id }}' -- required
AND ConsistencyLevel = '{{ ConsistencyLevel }}'
;

INSERT examples

Use this API to add an owner for the servicePrincipal. Service principal owners can be users, the service principal itself, or other service principals.

INSERT INTO entra_id.service_principals.owners (
directoryObjectId,
service_principal_id
)
SELECT
'{{ directoryObjectId }}',
'{{ service_principal_id }}'
;

DELETE examples

Remove an owner from a servicePrincipal object. As a recommended best practice, service principals should have at least two owners.

DELETE FROM entra_id.service_principals.owners
WHERE service_principal_id = '{{ service_principal_id }}' --required
AND directory_object_id = '{{ directory_object_id }}' --required
AND If-Match = '{{ If-Match }}'
;