Entra

How to get better with Graph API - Part one

· 3 min read · Entra

As you might know, Graph API is an important part of Microsoft 365. Everything (or most) of the things you see in the Entra admin center or Microsoft Admin portal is pulled from the Graph API. Every button you click pulls data from or pushes data to the Graph API.

An easy way to get to know the Graph API is to use your browser’s developer tools. Using the Network tab, you can spot any call to the Graph API. Let’s put it to the test.

We are going to create a new user and investigate what happens behind the curtains. Open the development tools, click the Network tab, and set the filter to Fetch/XHR. It will automatically record all network traffic.

With the development tools open, create a new user.

Screenshot from the article

Now, most of the API calls from the Entra admin center are put into batch commands. Instead of pushing API calls one by one, a batch API call is made, which can contain several API calls. Some calls are done independently, some are done in batch.

Screenshot from the article

To see what API calls are made, we need to explore the body (payload) of the API request. With batch calls, the payload is divided into an array, starting with 0,for the first call. When you expand that, you can look into the body and see what data was sent to the Graph API.

Screenshot from the article

The response tab will show you the response from the Graph API. This can be really handy for troubleshooting, as the information here is often not shown in the interface.

Screenshot from the article

The timing tab shows the call duration. This can be handy when you encounter a slow portal, for example.

Screenshot from the article

Now, let’s go a step further. The devtools are great, but if you really want to dig deeper into the Graph API, you can export your call (including your token) to tools like Postman.

Right-click on the batch (or any other) call, and click Copy -> Copy as cURL (bash).

Screenshot from the article

Now, from Postman, import the API call. Paste your copied cURL into Postman.

Screenshot from the article

Next, give it a name, and pick your collection of choice.

Screenshot from the article

Be careful! You have now copied a valid Entra session into Postman, so the API calls will be done in the context of the user from which you copied the request. When the bearer token is still valid (typically one hour), any new requests can be done from Postman without authentication. In this case, also the password of the new created user is copied, as it was stored in the body.#

You can now see the API endpoint, headers (including the bearer token), and the body.

Screenshot from the article

To make sense of the body, make sure you hit “Beatify”.

Screenshot from the article

So, let’s now create a new user in Postman by modifying the request body.

Screenshot from the article

Hit send, and see if the user is created successfully.

Screenshot from the article

We can also see the user reflected in the portal.

Screenshot from the article

That’s it for today.

I hope you learned some new tricks today, and see that studying the API calls can make you a better admin. Once you open up DevTools, a whole new world opens up. Stay tuned for part two, where we will intercept all API calls to Postman using a browser extension.

Stay safe.

Comments

Comments load when you scroll here.