claims_mapping_policies
Creates, updates, deletes, gets or lists a claims_mapping_policies resource.
Overview
| Name | claims_mapping_policies |
| Type | Resource |
| Id | entra_id.service_principals.claims_mapping_policies |
Fields
The following fields are returned by SELECT queries:
- list
Retrieved collection
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
appliesTo | array | |
definition | array | A string collection containing a JSON string that defines the rules and settings for a policy. The syntax for the definition differs for each derived policy type. Required. |
deletedDateTime | string (date-time) | Date and time when this object was deleted. Always null when the object hasn't been deleted. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
description | string | Description for this policy. Required. |
displayName | string | Display name for this policy. Required. |
isOrganizationDefault | boolean | If set to true, activates this policy. There can be many policies for the same policy type, but only one can be activated as the organization default. Optional, default value is false. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | service_principal_id | List the claimsMappingPolicy objects that are assigned to a servicePrincipal. | |
add_ref | insert | service_principal_id | Assign a claimsMappingPolicy to a servicePrincipal. | |
remove_ref | delete | service_principal_id, claims_mapping_policy_id | If-Match | Remove a claimsMappingPolicy from a servicePrincipal. |
remove_ref_2 | delete | service_principal_id | If-Match | Remove a claimsMappingPolicy from a servicePrincipal. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
claims_mapping_policy_id | string | The unique identifier of claimsMappingPolicy |
service_principal_id | string | The unique identifier of servicePrincipal |
If-Match | string | ETag |
SELECT examples
- list
List the claimsMappingPolicy objects that are assigned to a servicePrincipal.
SELECT
id,
appliesTo,
definition,
deletedDateTime,
description,
displayName,
isOrganizationDefault
FROM entra_id.service_principals.claims_mapping_policies
WHERE service_principal_id = '{{ service_principal_id }}' -- required
;
INSERT examples
- add_ref
- Manifest
Assign a claimsMappingPolicy to a servicePrincipal.
INSERT INTO entra_id.service_principals.claims_mapping_policies (
directoryObjectId,
service_principal_id
)
SELECT
'{{ directoryObjectId }}',
'{{ service_principal_id }}'
;
# Description fields are for documentation purposes
- name: claims_mapping_policies
props:
- name: service_principal_id
value: "{{ service_principal_id }}"
description: Required parameter for the claims_mapping_policies resource.
- name: directoryObjectId
value: "{{ directoryObjectId }}"
description: |
The id of the directory object to reference (a user, group, service principal, device, ...). Sent on the wire as '@odata.id': 'https://graph.microsoft.com/v1.0/directoryObjects/{id}'.
DELETE examples
- remove_ref
- remove_ref_2
Remove a claimsMappingPolicy from a servicePrincipal.
DELETE FROM entra_id.service_principals.claims_mapping_policies
WHERE service_principal_id = '{{ service_principal_id }}' --required
AND claims_mapping_policy_id = '{{ claims_mapping_policy_id }}' --required
AND If-Match = '{{ If-Match }}'
;
Remove a claimsMappingPolicy from a servicePrincipal.
DELETE FROM entra_id.service_principals.claims_mapping_policies
AND service_principal_id = '{{ service_principal_id }}' --required
AND If-Match = '{{ If-Match }}'
;