/api/v1/organization-members/{memberUuid}
Sets the member’s cumulative role. The last active Owner cannot be demoted. Requires the GV.APIOwner application role, or a higher role (Owner > Contributor > Reader).
Operation ID · update_organization_member
Request example
Authentication and access
- Required role: GV.APIOwner
- Data classification: metadata
- Side effects: configurationWrite
- Microsoft Entra delegated user token
- Microsoft Entra application token
Parameters
memberUuid
path Required Opaque Organization member UUID.string (uuid)
Opaque Organization member UUID.
If-Match
header Required Exact strong ETag from the current resource. Weak validators, wildcards, and tag lists are rejected.string
maximum length: 1024
Request body
Requiredapplication/json
Schema V1OrganizationMemberUpdateobject
Properties
role— Required
string
- Allowed values:
"reader","contributor","owner"
Responses
This guide summarizes response status codes and headers. Retrieve the deployed, authenticated OpenAPI document for the exact response body schemas and examples. The API also provides an authenticated Swagger UI; opening it in a browser does not automatically attach a bearer token. Error responses useapplication/problem+json. The response’s stable code and type map to the error-code reference.
200
Member role updated.Headers
- ETag:
string
401
A valid Microsoft Entra bearer token is required.403
The authenticated principal does not have the required role.404
The resource does not exist in this tenant.409
The operation conflicts with current resource or Azure state.412
If-Match did not match the resource’s current strong ETag.422
The request is syntactically valid but semantically invalid.428
The exact current ETag is required in If-Match.429
The bounded application request rate was exceeded.Headers
- Retry-After: Seconds to wait before retrying.
integerminimum: 1
503
A required dependency is temporarily unavailable.Headers
- Retry-After: Seconds to wait before retrying.
integerminimum: 1