entitlement_management_assignments_assignment_policy
Creates, updates, deletes, gets or lists an entitlement_management_assignments_assignment_policy resource.
Overview
| Name | entitlement_management_assignments_assignment_policy |
| Type | Resource |
| Id | entra_id.identity_governance.entitlement_management_assignments_assignment_policy |
Fields
The following fields are returned by SELECT queries:
- get
Retrieved navigation property
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
accessPackage | | Access package containing this policy. Read-only. Supports $expand. |
allowedTargetScope | | Principals that can be assigned the access package through this policy. The possible values are: notSpecified, specificDirectoryUsers, specificConnectedOrganizationUsers, specificDirectoryServicePrincipals, allMemberUsers, allDirectoryUsers, allDirectoryServicePrincipals, allConfiguredConnectedOrganizationUsers, allExternalUsers, allDirectoryAgentIdentities, unknownFutureValue. |
automaticRequestSettings | | This property is only present for an auto assignment policy; if absent, this is a request-based policy. |
catalog | | Catalog of the access package containing this policy. Read-only. |
createdDateTime | string (date-time) | The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
customExtensionStageSettings | array | The collection of stages when to execute one or more custom access package workflow extensions. Supports $expand. |
description | string | The description of the policy. |
displayName | string | The display name of the policy. |
expiration | | The expiration date for assignments created in this policy. |
modifiedDateTime | string (date-time) | The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
notificationSettings | | |
questions | array | Questions that are posed to the requestor. |
requestApprovalSettings | | Specifies the settings for approval of requests for an access package assignment through this policy. For example, if approval is required for new requests. |
requestorSettings | | Provides additional settings to select who can create a request for an access package assignment through this policy, and what they can include in their request. |
reviewSettings | | Settings for access reviews of assignments through this policy. |
specificAllowedTargets | array | The principals that can be assigned access from an access package through this policy. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | access_package_assignment_id | Read-only. Supports $filter (eq) on the id property and $expand query parameters. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
access_package_assignment_id | string | The unique identifier of accessPackageAssignment |
SELECT examples
- get
Read-only. Supports $filter (eq) on the id property and $expand query parameters.
SELECT
id,
accessPackage,
allowedTargetScope,
automaticRequestSettings,
catalog,
createdDateTime,
customExtensionStageSettings,
description,
displayName,
expiration,
modifiedDateTime,
notificationSettings,
questions,
requestApprovalSettings,
requestorSettings,
reviewSettings,
specificAllowedTargets
FROM entra_id.identity_governance.entitlement_management_assignments_assignment_policy
WHERE access_package_assignment_id = '{{ access_package_assignment_id }}' -- required
;