Skip to main content

token_lifetime_policies

Creates, updates, deletes, gets or lists a token_lifetime_policies resource.

Overview

Nametoken_lifetime_policies
TypeResource
Identra_id.service_principals.token_lifetime_policies

Fields

The following fields are returned by SELECT queries:

Retrieved collection

NameDatatypeDescription
idstringThe unique identifier for an entity. Read-only.
appliesToarray
definitionarrayA string collection containing a JSON string that defines the rules and settings for a policy. The syntax for the definition differs for each derived policy type. Required.
deletedDateTimestring (date-time)Date and time when this object was deleted. Always null when the object hasn't been deleted. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$)
descriptionstringDescription for this policy. Required.
displayNamestringDisplay name for this policy. Required.
isOrganizationDefaultbooleanIf set to true, activates this policy. There can be many policies for the same policy type, but only one can be activated as the organization default. Optional, default value is false.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectservice_principal_idList the tokenLifetimePolicy objects that are assigned to a servicePrincipal. Only one object is returned in the collection because only one tokenLifetimePolicy can be assigned to a service principal.
add_refinsertservice_principal_idAssign a tokenLifetimePolicy to a servicePrincipal. You can have multiple tokenLifetimePolicy policies in a tenant but can assign only one tokenLifetimePolicy per service principal.
remove_refdeleteservice_principal_id, token_lifetime_policy_idIf-MatchRemove a tokenLifetimePolicy object from a service principal.
remove_ref_2deleteservice_principal_idIf-MatchRemove a tokenLifetimePolicy object from a service principal.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
service_principal_idstringThe unique identifier of servicePrincipal
token_lifetime_policy_idstringThe unique identifier of tokenLifetimePolicy
If-MatchstringETag

SELECT examples

List the tokenLifetimePolicy objects that are assigned to a servicePrincipal. Only one object is returned in the collection because only one tokenLifetimePolicy can be assigned to a service principal.

SELECT
id,
appliesTo,
definition,
deletedDateTime,
description,
displayName,
isOrganizationDefault
FROM entra_id.service_principals.token_lifetime_policies
WHERE service_principal_id = '{{ service_principal_id }}' -- required
;

INSERT examples

Assign a tokenLifetimePolicy to a servicePrincipal. You can have multiple tokenLifetimePolicy policies in a tenant but can assign only one tokenLifetimePolicy per service principal.

INSERT INTO entra_id.service_principals.token_lifetime_policies (
directoryObjectId,
service_principal_id
)
SELECT
'{{ directoryObjectId }}',
'{{ service_principal_id }}'
;

DELETE examples

Remove a tokenLifetimePolicy object from a service principal.

DELETE FROM entra_id.service_principals.token_lifetime_policies
WHERE service_principal_id = '{{ service_principal_id }}' --required
AND token_lifetime_policy_id = '{{ token_lifetime_policy_id }}' --required
AND If-Match = '{{ If-Match }}'
;