app_management_policies
Creates, updates, deletes, gets or lists an app_management_policies resource.
Overview
| Name | app_management_policies |
| Type | Resource |
| Id | entra_id.applications.app_management_policies |
Fields
The following fields are returned by SELECT queries:
- list
Retrieved collection
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
appliesTo | array | Collection of applications and service principals to which the policy is applied. |
deletedDateTime | string (date-time) | Date and time when this object was deleted. Always null when the object hasn't been deleted. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
description | string | Description for this policy. Required. |
displayName | string | Display name for this policy. Required. |
isEnabled | boolean | Denotes whether the policy is enabled. |
restrictions | | Restrictions that apply to an application or service principal object. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | application_id | The appManagementPolicy applied to this application. | |
add_ref | insert | application_id | Assign an appManagementPolicy policy object to an application or service principal object. The application or service principal adopts this policy over the tenant-wide tenantAppManagementPolicy setting. Only one policy object can be assigned to an application or service principal. | |
remove_ref | delete | application_id, app_management_policy_id | If-Match | Remove an appManagementPolicy policy object from an application or service principal object. When you remove the appManagementPolicy, the application or service principal adopts the tenant-wide tenantAppManagementPolicy setting. |
remove_ref_2 | delete | application_id | If-Match | Remove an appManagementPolicy policy object from an application or service principal object. When you remove the appManagementPolicy, the application or service principal adopts the tenant-wide tenantAppManagementPolicy setting. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
app_management_policy_id | string | The unique identifier of appManagementPolicy |
application_id | string | The unique identifier of application |
If-Match | string | ETag |
SELECT examples
- list
The appManagementPolicy applied to this application.
SELECT
id,
appliesTo,
deletedDateTime,
description,
displayName,
isEnabled,
restrictions
FROM entra_id.applications.app_management_policies
WHERE application_id = '{{ application_id }}' -- required
;
INSERT examples
- add_ref
- Manifest
Assign an appManagementPolicy policy object to an application or service principal object. The application or service principal adopts this policy over the tenant-wide tenantAppManagementPolicy setting. Only one policy object can be assigned to an application or service principal.
INSERT INTO entra_id.applications.app_management_policies (
directoryObjectId,
application_id
)
SELECT
'{{ directoryObjectId }}',
'{{ application_id }}'
;
# Description fields are for documentation purposes
- name: app_management_policies
props:
- name: application_id
value: "{{ application_id }}"
description: Required parameter for the app_management_policies resource.
- name: directoryObjectId
value: "{{ directoryObjectId }}"
description: |
The id of the directory object to reference (a user, group, service principal, device, ...). Sent on the wire as '@odata.id': 'https://graph.microsoft.com/v1.0/directoryObjects/{id}'.
DELETE examples
- remove_ref
- remove_ref_2
Remove an appManagementPolicy policy object from an application or service principal object. When you remove the appManagementPolicy, the application or service principal adopts the tenant-wide tenantAppManagementPolicy setting.
DELETE FROM entra_id.applications.app_management_policies
WHERE application_id = '{{ application_id }}' --required
AND app_management_policy_id = '{{ app_management_policy_id }}' --required
AND If-Match = '{{ If-Match }}'
;
Remove an appManagementPolicy policy object from an application or service principal object. When you remove the appManagementPolicy, the application or service principal adopts the tenant-wide tenantAppManagementPolicy setting.
DELETE FROM entra_id.applications.app_management_policies
AND application_id = '{{ application_id }}' --required
AND If-Match = '{{ If-Match }}'
;