entitlement_management_role_eligibility_schedule_instances
Creates, updates, deletes, gets or lists an entitlement_management_role_eligibility_schedule_instances resource.
Overview
| Name | entitlement_management_role_eligibility_schedule_instances |
| Type | Resource |
| Id | entra_id.role_management.entitlement_management_role_eligibility_schedule_instances |
Fields
The following fields are returned by SELECT queries:
- get
- list
Retrieved navigation property
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
appScope | | Read-only property with details of the app-specific scope when the assignment or role eligibility is scoped to an app. Nullable. |
appScopeId | string | Identifier of the app-specific scope when the assignment or role eligibility is scoped to an app. The scope of an assignment or role eligibility determines the set of resources for which the principal has been granted access. App scopes are scopes that are defined and understood by this application only. Use / for tenant-wide app scopes. Use directoryScopeId to limit the scope to particular directory objects, for example, administrative units. |
directoryScope | | The directory object that is the scope of the assignment or role eligibility. Read-only. |
directoryScopeId | string | Identifier of the directory object representing the scope of the assignment or role eligibility. The scope of an assignment or role eligibility determines the set of resources for which the principal has been granted access. Directory scopes are shared scopes stored in the directory that are understood by multiple applications. Use / for tenant-wide scope. Use appScopeId to limit the scope to an application only. |
endDateTime | string (date-time) | The end date of the schedule instance. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
memberType | string | How the role eligibility is inherited. It can either be Inherited, Direct, or Group. It can further imply whether the unifiedRoleEligibilitySchedule can be managed by the caller. Supports $filter (eq, ne). |
principal | | The principal that's getting a role assignment or role eligibility through the request. |
principalId | string | Identifier of the principal that has been granted the role assignment or that's eligible for a role. |
roleDefinition | | Detailed information for the roleDefinition object that is referenced through the roleDefinitionId property. |
roleDefinitionId | string | Identifier of the unifiedRoleDefinition object that is being assigned to the principal or that the principal is eligible for. |
roleEligibilityScheduleId | string | The identifier of the unifiedRoleEligibilitySchedule object from which this instance was created. Supports $filter (eq, ne). |
startDateTime | string (date-time) | When this instance starts. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
Retrieved collection
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
appScope | | Read-only property with details of the app-specific scope when the assignment or role eligibility is scoped to an app. Nullable. |
appScopeId | string | Identifier of the app-specific scope when the assignment or role eligibility is scoped to an app. The scope of an assignment or role eligibility determines the set of resources for which the principal has been granted access. App scopes are scopes that are defined and understood by this application only. Use / for tenant-wide app scopes. Use directoryScopeId to limit the scope to particular directory objects, for example, administrative units. |
directoryScope | | The directory object that is the scope of the assignment or role eligibility. Read-only. |
directoryScopeId | string | Identifier of the directory object representing the scope of the assignment or role eligibility. The scope of an assignment or role eligibility determines the set of resources for which the principal has been granted access. Directory scopes are shared scopes stored in the directory that are understood by multiple applications. Use / for tenant-wide scope. Use appScopeId to limit the scope to an application only. |
endDateTime | string (date-time) | The end date of the schedule instance. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
memberType | string | How the role eligibility is inherited. It can either be Inherited, Direct, or Group. It can further imply whether the unifiedRoleEligibilitySchedule can be managed by the caller. Supports $filter (eq, ne). |
principal | | The principal that's getting a role assignment or role eligibility through the request. |
principalId | string | Identifier of the principal that has been granted the role assignment or that's eligible for a role. |
roleDefinition | | Detailed information for the roleDefinition object that is referenced through the roleDefinitionId property. |
roleDefinitionId | string | Identifier of the unifiedRoleDefinition object that is being assigned to the principal or that the principal is eligible for. |
roleEligibilityScheduleId | string | The identifier of the unifiedRoleEligibilitySchedule object from which this instance was created. Supports $filter (eq, ne). |
startDateTime | string (date-time) | When this instance starts. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | unified_role_eligibility_schedule_instance_id | Instances for role eligibility requests. | |
list | select | Instances for role eligibility requests. | ||
insert | insert | |||
update | update | unified_role_eligibility_schedule_instance_id | ||
delete | delete | unified_role_eligibility_schedule_instance_id | If-Match |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
unified_role_eligibility_schedule_instance_id | string | The unique identifier of unifiedRoleEligibilityScheduleInstance |
If-Match | string | ETag |
SELECT examples
- get
- list
Instances for role eligibility requests.
SELECT
id,
appScope,
appScopeId,
directoryScope,
directoryScopeId,
endDateTime,
memberType,
principal,
principalId,
roleDefinition,
roleDefinitionId,
roleEligibilityScheduleId,
startDateTime
FROM entra_id.role_management.entitlement_management_role_eligibility_schedule_instances
WHERE unified_role_eligibility_schedule_instance_id = '{{ unified_role_eligibility_schedule_instance_id }}' -- required
;
Instances for role eligibility requests.
SELECT
id,
appScope,
appScopeId,
directoryScope,
directoryScopeId,
endDateTime,
memberType,
principal,
principalId,
roleDefinition,
roleDefinitionId,
roleEligibilityScheduleId,
startDateTime
FROM entra_id.role_management.entitlement_management_role_eligibility_schedule_instances
;
INSERT examples
- insert
- Manifest
No description available.
INSERT INTO entra_id.role_management.entitlement_management_role_eligibility_schedule_instances (
id,
appScopeId,
directoryScopeId,
principalId,
roleDefinitionId,
appScope,
directoryScope,
principal,
roleDefinition,
endDateTime,
memberType,
roleEligibilityScheduleId,
startDateTime
)
SELECT
'{{ id }}',
'{{ appScopeId }}',
'{{ directoryScopeId }}',
'{{ principalId }}',
'{{ roleDefinitionId }}',
'{{ appScope }}',
'{{ directoryScope }}',
'{{ principal }}',
'{{ roleDefinition }}',
'{{ endDateTime }}',
'{{ memberType }}',
'{{ roleEligibilityScheduleId }}',
'{{ startDateTime }}'
RETURNING
id,
appScope,
appScopeId,
directoryScope,
directoryScopeId,
endDateTime,
memberType,
principal,
principalId,
roleDefinition,
roleDefinitionId,
roleEligibilityScheduleId,
startDateTime
;
# Description fields are for documentation purposes
- name: entitlement_management_role_eligibility_schedule_instances
props:
- name: id
value: "{{ id }}"
description: |
The unique identifier for an entity. Read-only.
- name: appScopeId
value: "{{ appScopeId }}"
description: |
Identifier of the app-specific scope when the assignment or role eligibility is scoped to an app. The scope of an assignment or role eligibility determines the set of resources for which the principal has been granted access. App scopes are scopes that are defined and understood by this application only. Use / for tenant-wide app scopes. Use directoryScopeId to limit the scope to particular directory objects, for example, administrative units.
- name: directoryScopeId
value: "{{ directoryScopeId }}"
description: |
Identifier of the directory object representing the scope of the assignment or role eligibility. The scope of an assignment or role eligibility determines the set of resources for which the principal has been granted access. Directory scopes are shared scopes stored in the directory that are understood by multiple applications. Use / for tenant-wide scope. Use appScopeId to limit the scope to an application only.
- name: principalId
value: "{{ principalId }}"
description: |
Identifier of the principal that has been granted the role assignment or that's eligible for a role.
- name: roleDefinitionId
value: "{{ roleDefinitionId }}"
description: |
Identifier of the unifiedRoleDefinition object that is being assigned to the principal or that the principal is eligible for.
- name: appScope
value: "{{ appScope }}"
description: |
Read-only property with details of the app-specific scope when the assignment or role eligibility is scoped to an app. Nullable.
- name: directoryScope
value: "{{ directoryScope }}"
description: |
The directory object that is the scope of the assignment or role eligibility. Read-only.
- name: principal
value: "{{ principal }}"
description: |
The principal that's getting a role assignment or role eligibility through the request.
- name: roleDefinition
value: "{{ roleDefinition }}"
description: |
Detailed information for the roleDefinition object that is referenced through the roleDefinitionId property.
- name: endDateTime
value: "{{ endDateTime }}"
description: |
The end date of the schedule instance.
- name: memberType
value: "{{ memberType }}"
description: |
How the role eligibility is inherited. It can either be Inherited, Direct, or Group. It can further imply whether the unifiedRoleEligibilitySchedule can be managed by the caller. Supports $filter (eq, ne).
- name: roleEligibilityScheduleId
value: "{{ roleEligibilityScheduleId }}"
description: |
The identifier of the unifiedRoleEligibilitySchedule object from which this instance was created. Supports $filter (eq, ne).
- name: startDateTime
value: "{{ startDateTime }}"
description: |
When this instance starts.
UPDATE examples
- update
No description available.
UPDATE entra_id.role_management.entitlement_management_role_eligibility_schedule_instances
SET
id = '{{ id }}',
appScopeId = '{{ appScopeId }}',
directoryScopeId = '{{ directoryScopeId }}',
principalId = '{{ principalId }}',
roleDefinitionId = '{{ roleDefinitionId }}',
appScope = '{{ appScope }}',
directoryScope = '{{ directoryScope }}',
principal = '{{ principal }}',
roleDefinition = '{{ roleDefinition }}',
endDateTime = '{{ endDateTime }}',
memberType = '{{ memberType }}',
roleEligibilityScheduleId = '{{ roleEligibilityScheduleId }}',
startDateTime = '{{ startDateTime }}'
WHERE
unified_role_eligibility_schedule_instance_id = '{{ unified_role_eligibility_schedule_instance_id }}' --required
RETURNING
id,
appScope,
appScopeId,
directoryScope,
directoryScopeId,
endDateTime,
memberType,
principal,
principalId,
roleDefinition,
roleDefinitionId,
roleEligibilityScheduleId,
startDateTime;
DELETE examples
- delete
No description available.
DELETE FROM entra_id.role_management.entitlement_management_role_eligibility_schedule_instances
WHERE unified_role_eligibility_schedule_instance_id = '{{ unified_role_eligibility_schedule_instance_id }}' --required
AND If-Match = '{{ If-Match }}'
;