directory_role_eligibility_schedule_requests
Creates, updates, deletes, gets or lists a directory_role_eligibility_schedule_requests resource.
Overview
| Name | directory_role_eligibility_schedule_requests |
| Type | Resource |
| Id | entra_id.role_management.directory_role_eligibility_schedule_requests |
Fields
The following fields are returned by SELECT queries:
- get
- list
Retrieved navigation property
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
action | | Represents the type of operation on the role eligibility request. The possible values are: adminAssign, adminUpdate, adminRemove, selfActivate, selfDeactivate, adminExtend, adminRenew, selfExtend, selfRenew, unknownFutureValue. adminAssign: For administrators to assign eligible roles to principals.adminRemove: For administrators to remove eligible roles from principals. adminUpdate: For administrators to change existing role eligibilities.adminExtend: For administrators to extend expiring role eligibilities.adminRenew: For administrators to renew expired eligibilities.selfActivate: For users to activate their assignments.selfDeactivate: For users to deactivate their active assignments.selfExtend: For users to request to extend their expiring assignments.selfRenew: For users to request to renew their expired assignments. |
appScope | | Read-only property with details of the app-specific scope when the role eligibility is scoped to an app. Nullable. Supports $expand. |
appScopeId | string | Identifier of the app-specific scope when the role eligibility is scoped to an app. The scope of a role eligibility determines the set of resources for which the principal is eligible to access. App scopes are scopes that are defined and understood by this application only. Use / for tenant-wide app scopes. Use directoryScopeId to limit the scope to particular directory objects, for example, administrative units. Supports $filter (eq, ne, and on null values). |
approvalId | string | The identifier of the approval of the request. |
completedDateTime | string (date-time) | The request completion date time. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
createdBy | | The principal that created the request. |
createdDateTime | string (date-time) | The request creation date time. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
customData | string | Free text field to define any custom data for the request. Not used. |
directoryScope | | The directory object that is the scope of the role eligibility. Read-only. Supports $expand. |
directoryScopeId | string | Identifier of the directory object representing the scope of the role eligibility. The scope of a role eligibility determines the set of resources for which the principal has been granted access. Directory scopes are shared scopes stored in the directory that are understood by multiple applications. Use / for tenant-wide scope. Use appScopeId to limit the scope to an application only. Supports $filter (eq, ne, and on null values). |
isValidationOnly | boolean | Determines whether the call is a validation or an actual call. Only set this property if you want to check whether an activation is subject to additional rules like MFA before actually submitting the request. |
justification | string | A message provided by users and administrators when create they create the unifiedRoleEligibilityScheduleRequest object. |
principal | | The principal that's getting a role eligibility through the request. Supports $expand. |
principalId | string | Identifier of the principal that has been granted the role eligibility. Can be a user or a role-assignable group. You can grant only active assignments service principals.Supports $filter (eq, ne). |
roleDefinition | | Detailed information for the unifiedRoleDefinition object that is referenced through the roleDefinitionId property. Supports $expand. |
roleDefinitionId | string | Identifier of the unifiedRoleDefinition object that is being assigned to the principal. Supports $filter (eq, ne). |
scheduleInfo | | The period of the role eligibility. Recurring schedules are currently unsupported. |
status | string | The status of the request. Not nullable. The possible values are: Canceled, Denied, Failed, Granted, PendingAdminDecision, PendingApproval, PendingProvisioning, PendingScheduleCreation, Provisioned, Revoked, and ScheduleCreated. Not nullable. |
targetSchedule | | The schedule for a role eligibility that is referenced through the targetScheduleId property. Supports $expand. |
targetScheduleId | string | Identifier of the schedule object that's linked to the eligibility request. Supports $filter (eq, ne). |
ticketInfo | | Ticket details linked to the role eligibility request including details of the ticket number and ticket system. Optional. |
Retrieved collection
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
action | | Represents the type of operation on the role eligibility request. The possible values are: adminAssign, adminUpdate, adminRemove, selfActivate, selfDeactivate, adminExtend, adminRenew, selfExtend, selfRenew, unknownFutureValue. adminAssign: For administrators to assign eligible roles to principals.adminRemove: For administrators to remove eligible roles from principals. adminUpdate: For administrators to change existing role eligibilities.adminExtend: For administrators to extend expiring role eligibilities.adminRenew: For administrators to renew expired eligibilities.selfActivate: For users to activate their assignments.selfDeactivate: For users to deactivate their active assignments.selfExtend: For users to request to extend their expiring assignments.selfRenew: For users to request to renew their expired assignments. |
appScope | | Read-only property with details of the app-specific scope when the role eligibility is scoped to an app. Nullable. Supports $expand. |
appScopeId | string | Identifier of the app-specific scope when the role eligibility is scoped to an app. The scope of a role eligibility determines the set of resources for which the principal is eligible to access. App scopes are scopes that are defined and understood by this application only. Use / for tenant-wide app scopes. Use directoryScopeId to limit the scope to particular directory objects, for example, administrative units. Supports $filter (eq, ne, and on null values). |
approvalId | string | The identifier of the approval of the request. |
completedDateTime | string (date-time) | The request completion date time. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
createdBy | | The principal that created the request. |
createdDateTime | string (date-time) | The request creation date time. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
customData | string | Free text field to define any custom data for the request. Not used. |
directoryScope | | The directory object that is the scope of the role eligibility. Read-only. Supports $expand. |
directoryScopeId | string | Identifier of the directory object representing the scope of the role eligibility. The scope of a role eligibility determines the set of resources for which the principal has been granted access. Directory scopes are shared scopes stored in the directory that are understood by multiple applications. Use / for tenant-wide scope. Use appScopeId to limit the scope to an application only. Supports $filter (eq, ne, and on null values). |
isValidationOnly | boolean | Determines whether the call is a validation or an actual call. Only set this property if you want to check whether an activation is subject to additional rules like MFA before actually submitting the request. |
justification | string | A message provided by users and administrators when create they create the unifiedRoleEligibilityScheduleRequest object. |
principal | | The principal that's getting a role eligibility through the request. Supports $expand. |
principalId | string | Identifier of the principal that has been granted the role eligibility. Can be a user or a role-assignable group. You can grant only active assignments service principals.Supports $filter (eq, ne). |
roleDefinition | | Detailed information for the unifiedRoleDefinition object that is referenced through the roleDefinitionId property. Supports $expand. |
roleDefinitionId | string | Identifier of the unifiedRoleDefinition object that is being assigned to the principal. Supports $filter (eq, ne). |
scheduleInfo | | The period of the role eligibility. Recurring schedules are currently unsupported. |
status | string | The status of the request. Not nullable. The possible values are: Canceled, Denied, Failed, Granted, PendingAdminDecision, PendingApproval, PendingProvisioning, PendingScheduleCreation, Provisioned, Revoked, and ScheduleCreated. Not nullable. |
targetSchedule | | The schedule for a role eligibility that is referenced through the targetScheduleId property. Supports $expand. |
targetScheduleId | string | Identifier of the schedule object that's linked to the eligibility request. Supports $filter (eq, ne). |
ticketInfo | | Ticket details linked to the role eligibility request including details of the ticket number and ticket system. Optional. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | unified_role_eligibility_schedule_request_id | In PIM, read the details of a request for for a role eligibility request made through the unifiedRoleEligibilityScheduleRequest object. | |
list | select | In PIM, retrieve the requests for role eligibilities for principals made through the unifiedRoleEligibilityScheduleRequest object. | ||
insert | insert | In PIM, request for a role eligibility for a principal through the unifiedRoleEligibilityScheduleRequest object. This operation allows both admins and eligible users to add, revoke, or extend eligible assignments. | ||
update | update | unified_role_eligibility_schedule_request_id | ||
delete | delete | unified_role_eligibility_schedule_request_id | If-Match | |
cancel | exec | unified_role_eligibility_schedule_request_id | Immediately cancel a unifiedRoleEligibilityScheduleRequest object whose status is Granted and have the system automatically delete the cancelled request after 30 days. After calling this action, the status of the cancelled unifiedRoleEligibilityScheduleRequest changes to Revoked. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
unified_role_eligibility_schedule_request_id | string | The unique identifier of unifiedRoleEligibilityScheduleRequest |
If-Match | string | ETag |
SELECT examples
- get
- list
In PIM, read the details of a request for for a role eligibility request made through the unifiedRoleEligibilityScheduleRequest object.
SELECT
id,
action,
appScope,
appScopeId,
approvalId,
completedDateTime,
createdBy,
createdDateTime,
customData,
directoryScope,
directoryScopeId,
isValidationOnly,
justification,
principal,
principalId,
roleDefinition,
roleDefinitionId,
scheduleInfo,
status,
targetSchedule,
targetScheduleId,
ticketInfo
FROM entra_id.role_management.directory_role_eligibility_schedule_requests
WHERE unified_role_eligibility_schedule_request_id = '{{ unified_role_eligibility_schedule_request_id }}' -- required
;
In PIM, retrieve the requests for role eligibilities for principals made through the unifiedRoleEligibilityScheduleRequest object.
SELECT
id,
action,
appScope,
appScopeId,
approvalId,
completedDateTime,
createdBy,
createdDateTime,
customData,
directoryScope,
directoryScopeId,
isValidationOnly,
justification,
principal,
principalId,
roleDefinition,
roleDefinitionId,
scheduleInfo,
status,
targetSchedule,
targetScheduleId,
ticketInfo
FROM entra_id.role_management.directory_role_eligibility_schedule_requests
;
INSERT examples
- insert
- Manifest
In PIM, request for a role eligibility for a principal through the unifiedRoleEligibilityScheduleRequest object. This operation allows both admins and eligible users to add, revoke, or extend eligible assignments.
INSERT INTO entra_id.role_management.directory_role_eligibility_schedule_requests (
id,
approvalId,
completedDateTime,
createdBy,
createdDateTime,
customData,
status,
action,
appScopeId,
directoryScopeId,
isValidationOnly,
justification,
principalId,
roleDefinitionId,
scheduleInfo,
targetScheduleId,
ticketInfo,
appScope,
directoryScope,
principal,
roleDefinition,
targetSchedule
)
SELECT
'{{ id }}',
'{{ approvalId }}',
'{{ completedDateTime }}',
'{{ createdBy }}',
'{{ createdDateTime }}',
'{{ customData }}',
'{{ status }}',
'{{ action }}',
'{{ appScopeId }}',
'{{ directoryScopeId }}',
{{ isValidationOnly }},
'{{ justification }}',
'{{ principalId }}',
'{{ roleDefinitionId }}',
'{{ scheduleInfo }}',
'{{ targetScheduleId }}',
'{{ ticketInfo }}',
'{{ appScope }}',
'{{ directoryScope }}',
'{{ principal }}',
'{{ roleDefinition }}',
'{{ targetSchedule }}'
RETURNING
id,
action,
appScope,
appScopeId,
approvalId,
completedDateTime,
createdBy,
createdDateTime,
customData,
directoryScope,
directoryScopeId,
isValidationOnly,
justification,
principal,
principalId,
roleDefinition,
roleDefinitionId,
scheduleInfo,
status,
targetSchedule,
targetScheduleId,
ticketInfo
;
# Description fields are for documentation purposes
- name: directory_role_eligibility_schedule_requests
props:
- name: id
value: "{{ id }}"
description: |
The unique identifier for an entity. Read-only.
- name: approvalId
value: "{{ approvalId }}"
description: |
The identifier of the approval of the request.
- name: completedDateTime
value: "{{ completedDateTime }}"
description: |
The request completion date time.
- name: createdBy
value: "{{ createdBy }}"
description: |
The principal that created the request.
- name: createdDateTime
value: "{{ createdDateTime }}"
description: |
The request creation date time.
- name: customData
value: "{{ customData }}"
description: |
Free text field to define any custom data for the request. Not used.
- name: status
value: "{{ status }}"
description: |
The status of the request. Not nullable. The possible values are: Canceled, Denied, Failed, Granted, PendingAdminDecision, PendingApproval, PendingProvisioning, PendingScheduleCreation, Provisioned, Revoked, and ScheduleCreated. Not nullable.
- name: action
value: "{{ action }}"
description: |
Represents the type of operation on the role eligibility request. The possible values are: adminAssign, adminUpdate, adminRemove, selfActivate, selfDeactivate, adminExtend, adminRenew, selfExtend, selfRenew, unknownFutureValue. adminAssign: For administrators to assign eligible roles to principals.adminRemove: For administrators to remove eligible roles from principals. adminUpdate: For administrators to change existing role eligibilities.adminExtend: For administrators to extend expiring role eligibilities.adminRenew: For administrators to renew expired eligibilities.selfActivate: For users to activate their assignments.selfDeactivate: For users to deactivate their active assignments.selfExtend: For users to request to extend their expiring assignments.selfRenew: For users to request to renew their expired assignments.
- name: appScopeId
value: "{{ appScopeId }}"
description: |
Identifier of the app-specific scope when the role eligibility is scoped to an app. The scope of a role eligibility determines the set of resources for which the principal is eligible to access. App scopes are scopes that are defined and understood by this application only. Use / for tenant-wide app scopes. Use directoryScopeId to limit the scope to particular directory objects, for example, administrative units. Supports $filter (eq, ne, and on null values).
- name: directoryScopeId
value: "{{ directoryScopeId }}"
description: |
Identifier of the directory object representing the scope of the role eligibility. The scope of a role eligibility determines the set of resources for which the principal has been granted access. Directory scopes are shared scopes stored in the directory that are understood by multiple applications. Use / for tenant-wide scope. Use appScopeId to limit the scope to an application only. Supports $filter (eq, ne, and on null values).
- name: isValidationOnly
value: {{ isValidationOnly }}
description: |
Determines whether the call is a validation or an actual call. Only set this property if you want to check whether an activation is subject to additional rules like MFA before actually submitting the request.
- name: justification
value: "{{ justification }}"
description: |
A message provided by users and administrators when create they create the unifiedRoleEligibilityScheduleRequest object.
- name: principalId
value: "{{ principalId }}"
description: |
Identifier of the principal that has been granted the role eligibility. Can be a user or a role-assignable group. You can grant only active assignments service principals.Supports $filter (eq, ne).
- name: roleDefinitionId
value: "{{ roleDefinitionId }}"
description: |
Identifier of the unifiedRoleDefinition object that is being assigned to the principal. Supports $filter (eq, ne).
- name: scheduleInfo
value: "{{ scheduleInfo }}"
description: |
The period of the role eligibility. Recurring schedules are currently unsupported.
- name: targetScheduleId
value: "{{ targetScheduleId }}"
description: |
Identifier of the schedule object that's linked to the eligibility request. Supports $filter (eq, ne).
- name: ticketInfo
value: "{{ ticketInfo }}"
description: |
Ticket details linked to the role eligibility request including details of the ticket number and ticket system. Optional.
- name: appScope
value: "{{ appScope }}"
description: |
Read-only property with details of the app-specific scope when the role eligibility is scoped to an app. Nullable. Supports $expand.
- name: directoryScope
value: "{{ directoryScope }}"
description: |
The directory object that is the scope of the role eligibility. Read-only. Supports $expand.
- name: principal
value: "{{ principal }}"
description: |
The principal that's getting a role eligibility through the request. Supports $expand.
- name: roleDefinition
value: "{{ roleDefinition }}"
description: |
Detailed information for the unifiedRoleDefinition object that is referenced through the roleDefinitionId property. Supports $expand.
- name: targetSchedule
value: "{{ targetSchedule }}"
description: |
The schedule for a role eligibility that is referenced through the targetScheduleId property. Supports $expand.
UPDATE examples
- update
No description available.
UPDATE entra_id.role_management.directory_role_eligibility_schedule_requests
SET
id = '{{ id }}',
approvalId = '{{ approvalId }}',
completedDateTime = '{{ completedDateTime }}',
createdBy = '{{ createdBy }}',
createdDateTime = '{{ createdDateTime }}',
customData = '{{ customData }}',
status = '{{ status }}',
action = '{{ action }}',
appScopeId = '{{ appScopeId }}',
directoryScopeId = '{{ directoryScopeId }}',
isValidationOnly = {{ isValidationOnly }},
justification = '{{ justification }}',
principalId = '{{ principalId }}',
roleDefinitionId = '{{ roleDefinitionId }}',
scheduleInfo = '{{ scheduleInfo }}',
targetScheduleId = '{{ targetScheduleId }}',
ticketInfo = '{{ ticketInfo }}',
appScope = '{{ appScope }}',
directoryScope = '{{ directoryScope }}',
principal = '{{ principal }}',
roleDefinition = '{{ roleDefinition }}',
targetSchedule = '{{ targetSchedule }}'
WHERE
unified_role_eligibility_schedule_request_id = '{{ unified_role_eligibility_schedule_request_id }}' --required
RETURNING
id,
action,
appScope,
appScopeId,
approvalId,
completedDateTime,
createdBy,
createdDateTime,
customData,
directoryScope,
directoryScopeId,
isValidationOnly,
justification,
principal,
principalId,
roleDefinition,
roleDefinitionId,
scheduleInfo,
status,
targetSchedule,
targetScheduleId,
ticketInfo;
DELETE examples
- delete
No description available.
DELETE FROM entra_id.role_management.directory_role_eligibility_schedule_requests
WHERE unified_role_eligibility_schedule_request_id = '{{ unified_role_eligibility_schedule_request_id }}' --required
AND If-Match = '{{ If-Match }}'
;
Lifecycle Methods
- cancel
Immediately cancel a unifiedRoleEligibilityScheduleRequest object whose status is Granted and have the system automatically delete the cancelled request after 30 days. After calling this action, the status of the cancelled unifiedRoleEligibilityScheduleRequest changes to Revoked.
EXEC entra_id.role_management.directory_role_eligibility_schedule_requests.cancel
@unified_role_eligibility_schedule_request_id='{{ unified_role_eligibility_schedule_request_id }}' --required
;