Skip to main content

msgraph-py

Description

This package contains API wrappers to simplify interaction with Microsoft Graph API through Python functions.

Some of the benefits of msgraph-py are:

  • Automatic caching and renewal of access tokens, avoiding unnecessary API-calls.
  • Sets the correct headers and parameters for you when required (advanced queries).
  • Pages results automatically when retrieving large datasets.
  • Useful logging and error messages with the Python logging module.
  • Optional integration with Django settings.py for reading environment variables.

List of available functions

Identity

  • get_user()
  • get_user_risk()
  • revoke_refresh_tokens()
  • list_auth_methods()
  • delete_auth_method()
  • reset_strong_auth()
  • get_signin()

Groups

  • get_group()
  • list_group_members()
  • add_group_member()
  • remove_group_member()

Devices

  • get_device()
  • delete_device()
  • list_owned_devices()
  • get_laps_password()

Mail

  • send_mail()

Getting Started

  1. Create an app registration in Entra ID with the necessary Graph application permissions for the functions you intend to use:
    Authentication and authorization steps

  2. Install the latest version of the package:

    python3 -m pip install msgraph-py
    
  3. Configure environment variables:

    • If used within a Django project, msgraph-py will by default first attempt to load the following variables from the project's settings.py:

      # project/settings.py
      
      AAD_TENANT_ID = "00000000-0000-0000-0000-000000000000"
      AAD_CLIENT_ID = "00000000-0000-0000-0000-000000000000"
      AAD_CLIENT_SECRET = "client-secret-value"
      
    • Alternatively you will need to set the following key-value pairs in os.environ:

      import os
      
      os.environ["AAD_TENANT_ID"] = "00000000-0000-0000-0000-000000000000"
      os.environ["AAD_CLIENT_ID"] = "00000000-0000-0000-0000-000000000000"
      os.environ["AAD_CLIENT_SECRET"] = "client-secret-value"
      

Certificate-based authentication

For improved security, consider migrating to certificate-based authentication instead of a static client secret. The simplest way to do this is using the openssl command to create a self-signed certificate and private key:

hostname=$(hostname -s)
fqdn=$(hostname -f)

openssl req \
    -x509 \
    -newkey rsa:2048 \
    -sha256 \
    -days 3650 \
    -subj "/CN=${fqdn}" \
    -keyout "${hostname}_key.pem" \
    -out "${hostname}_cert.pem" \
    -noenc \
    &> /dev/null

Upload the certificate PEM-file to the app registration in Microsoft Entra ID. Make a note of the certificate thumbprint, as we will be needing this in the next step. See Microsofts documentation on adding credentials for more info.

Remove AAD_CLIENT_SECRET from your configuration and set the following environment variables (or settings.py) instead:

os.environ["AAD_PRIVATE_KEY_PATH"] = "path/to/private_key.pem"

# Alternatively pass the key data directly (only PEM-format supported)
os.environ["AAD_PRIVATE_KEY"] = "-----BEGIN PRIVATE KEY-----...-----END PRIVATE KEY-----"

# Required if the private key is password-protected
os.environ["AAD_PRIVATE_KEY_PASSPHRASE"] = "key-passphrase-value"

# Required if the private key does not contain a X.509 certificate
os.environ["AAD_CERT_THUMBPRINT"] = "cert-thumbprint-value"

Usage examples

Get a single user by objectId or userPrincipalName

from msgraph import get_user

user = get_user("user@example.com")

List of returned properties for user resource type.

Get a list of users using advanced query parameters

from msgraph import get_user

filtered_users = get_user(
    filter="startsWith(department, 'sales')",
    select=[
        "displayName",
        "department",
        "createdDateTime",
    ],
    orderby="createdDateTime desc",
    all=True,
)

List of returned properties for user resource type.

Get a users Entra ID joined devices

from msgraph import list_owned_devices

user_devices = list_owned_devices(
    user_id="user@example.com",
    filter="isManaged eq true and trustType eq 'AzureAd'",
    select=[
        "deviceId",
        "displayName",
        "isCompliant",
        "approximateLastSignInDateTime",
    ],
    orderby="approximateLastSignInDateTime desc",
)

List of returned properties for device resource type.

Send an e-mail with attachments

from msgraph import send_mail

send_mail(
    sender_id="noreply@example.com",
    recipients=[
        "john.doe@example.com",
        "jane.doe@example.com",
    ],
    subject="Mail from Graph API",
    body="<h1>Content of the mail body</h1>",
    is_html=True,
    priority="high",
    attachments=[
        "/path/to/file1.txt",
        "/path/to/file2.txt",
    ],
)

API documentation

Resource types and properties

Release files for msgraph-py 1.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for msgraph-py 1.5.0
File Size Uploaded
msgraph_py-1.5.0.tar.gz 21.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for msgraph-py 1.5.0
File Interpreter ABI Platform
msgraph_py-1.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 40.5 kB

Release files / msgraph_py-1.5.0.tar.gz

Download URL msgraph_py-1.5.0.tar.gz
Size 21.3 kB
Tags Source
SHA-256 checksum
How to use checksums
ef81c989063a366c59d90b313e3ddb531d6976671ef8281ba543daa4287b05ef
BLAKE2b-256 checksum
How to use checksums
f911c6f2d4937a2dc44f215c9f58be9cc8a0dac2da11d4fa27f20d96bad99cb2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 14, 2026.

Transparency log

Release files / msgraph_py-1.5.0-py3-none-any.whl

Download URL msgraph_py-1.5.0-py3-none-any.whl
Size 19.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
46206959e416cc304e6697eb2cddd70d9b52607487ebfc5a46f8a9205f499d4e
BLAKE2b-256 checksum
How to use checksums
ca8849337fe98b80560feebee0efda02e49877ae2398e7fec323c63fcfafa5be
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 14, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.5.0 This release

2 release files

1.4.1

2 release files

1.4.0

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page