请求Microsoft Graph提供查询非Graph创建的AD/B2C旧扩展的API
schemaExtensions It sounds like you're dealing with Directory Extensions (the extension_XXXXX_name format properties) rather than Microsoft Graph's Schema Extensions. These are two distinct types of extensions, which is why you can't find them in the schemaExtensions endpoint results. Directory Extensions are typically created via Azure AD PowerShell, the Azure Portal, or the old Azure AD Graph API—not through the Microsoft Graph schemaExtensions API.
Here are the most reliable ways to retrieve these extensions' names and identifiers:
1. Query the Extension Properties of the Creating Application
Directory Extensions are tied to the Azure AD application that created them. You can fetch all extensions linked to a specific app using this Microsoft Graph endpoint:
curl -X GET "https://graph.microsoft.com/v1.0/applications/{application-id}/extensionProperties" -H "accept: application/json" -H "Authorization: Bearer TOKEN"
- Replace
{application-id}with the object ID of the app that originally created the extensions. - The response will include the full
name(e.g.,extension_XXXXX_name) and details like which object types (targetObjects) the extension applies to (e.g.,User).
If you don't know which app created the extensions, you can iterate over all registered apps and their extension properties (requires the Application.Read.All or Directory.Read.All permission):
curl -X GET "https://graph.microsoft.com/v1.0/applications?expand=extensionProperties" -H "accept: application/json" -H "Authorization: Bearer TOKEN"
2. Fetch User Properties with $select=* (For User-Targeted Extensions)
If you know the extensions are applied to user objects, you can try requesting all properties for a specific user:
curl -X GET "https://graph.microsoft.com/v1.0/users/{user-id}?$select=*" -H "accept: application/json" -H "Authorization: Bearer TOKEN"
⚠️ Note: This only returns extensions that have a value set on the user. If an extension is empty for that user, it won't appear in the response.
3. Use Azure AD PowerShell (If Permitted)
If you have access to Azure AD PowerShell modules, you can list all directory extensions across your tenant with this command:
Get-AzureADApplication | ForEach-Object { Get-AzureADApplicationExtensionProperty -ObjectId $_.ObjectId }
The Name field in the output will give you the full extension_XXXXX_name format you need for $select queries.
Currently, Microsoft Graph doesn't have a single endpoint to list all directory extensions across all applications in one go. Iterating over apps' extensionProperties is the most consistent method to uncover all your old extensions, even those you don't know the names of yet.
内容的提问来源于stack exchange,提问作者UberFace

