deny_assignments
Creates, updates, deletes, gets or lists a deny_assignments resource.
Overview
| Name | deny_assignments |
| Type | Resource |
| Id | azure.authorization.deny_assignments |
Fields
The following fields are returned by SELECT queries:
- list_for_resource
- get
- list_for_resource_group
- list
- list_for_scope
- get_by_id
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the deny assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
denyAssignmentEffect | string | The effect of the deny assignment. 'enforced' blocks access, 'audit' logs without blocking. Known values are: "enforced" and "audit". (enforced, audit) |
denyAssignmentName | string | The display name of the deny assignment. |
description | string | The description of the deny assignment. |
doNotApplyToChildScopes | boolean | Determines if the deny assignment applies to child scopes. Default value is false. |
excludePrincipals | array | Array of principals to which the deny assignment does not apply. |
isSystemProtected | boolean | Specifies whether this deny assignment was created by Azure and cannot be edited or deleted. |
permissions | array | An array of permissions that are denied by the deny assignment. |
principals | array | Array of principals to which the deny assignment applies. |
scope | string | The deny assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the deny assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
denyAssignmentEffect | string | The effect of the deny assignment. 'enforced' blocks access, 'audit' logs without blocking. Known values are: "enforced" and "audit". (enforced, audit) |
denyAssignmentName | string | The display name of the deny assignment. |
description | string | The description of the deny assignment. |
doNotApplyToChildScopes | boolean | Determines if the deny assignment applies to child scopes. Default value is false. |
excludePrincipals | array | Array of principals to which the deny assignment does not apply. |
isSystemProtected | boolean | Specifies whether this deny assignment was created by Azure and cannot be edited or deleted. |
permissions | array | An array of permissions that are denied by the deny assignment. |
principals | array | Array of principals to which the deny assignment applies. |
scope | string | The deny assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the deny assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
denyAssignmentEffect | string | The effect of the deny assignment. 'enforced' blocks access, 'audit' logs without blocking. Known values are: "enforced" and "audit". (enforced, audit) |
denyAssignmentName | string | The display name of the deny assignment. |
description | string | The description of the deny assignment. |
doNotApplyToChildScopes | boolean | Determines if the deny assignment applies to child scopes. Default value is false. |
excludePrincipals | array | Array of principals to which the deny assignment does not apply. |
isSystemProtected | boolean | Specifies whether this deny assignment was created by Azure and cannot be edited or deleted. |
permissions | array | An array of permissions that are denied by the deny assignment. |
principals | array | Array of principals to which the deny assignment applies. |
scope | string | The deny assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the deny assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
denyAssignmentEffect | string | The effect of the deny assignment. 'enforced' blocks access, 'audit' logs without blocking. Known values are: "enforced" and "audit". (enforced, audit) |
denyAssignmentName | string | The display name of the deny assignment. |
description | string | The description of the deny assignment. |
doNotApplyToChildScopes | boolean | Determines if the deny assignment applies to child scopes. Default value is false. |
excludePrincipals | array | Array of principals to which the deny assignment does not apply. |
isSystemProtected | boolean | Specifies whether this deny assignment was created by Azure and cannot be edited or deleted. |
permissions | array | An array of permissions that are denied by the deny assignment. |
principals | array | Array of principals to which the deny assignment applies. |
scope | string | The deny assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the deny assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
denyAssignmentEffect | string | The effect of the deny assignment. 'enforced' blocks access, 'audit' logs without blocking. Known values are: "enforced" and "audit". (enforced, audit) |
denyAssignmentName | string | The display name of the deny assignment. |
description | string | The description of the deny assignment. |
doNotApplyToChildScopes | boolean | Determines if the deny assignment applies to child scopes. Default value is false. |
excludePrincipals | array | Array of principals to which the deny assignment does not apply. |
isSystemProtected | boolean | Specifies whether this deny assignment was created by Azure and cannot be edited or deleted. |
permissions | array | An array of permissions that are denied by the deny assignment. |
principals | array | Array of principals to which the deny assignment applies. |
scope | string | The deny assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the deny assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
denyAssignmentEffect | string | The effect of the deny assignment. 'enforced' blocks access, 'audit' logs without blocking. Known values are: "enforced" and "audit". (enforced, audit) |
denyAssignmentName | string | The display name of the deny assignment. |
description | string | The description of the deny assignment. |
doNotApplyToChildScopes | boolean | Determines if the deny assignment applies to child scopes. Default value is false. |
excludePrincipals | array | Array of principals to which the deny assignment does not apply. |
isSystemProtected | boolean | Specifies whether this deny assignment was created by Azure and cannot be edited or deleted. |
permissions | array | An array of permissions that are denied by the deny assignment. |
principals | array | Array of principals to which the deny assignment applies. |
scope | string | The deny assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list_for_resource | select | resource_group_name, resource_provider_namespace, parent_resource_path, resource_type, resource_name, subscription_id | $filter | Gets deny assignments for a resource. |
get | select | scope, deny_assignment_id | Get the specified deny assignment. | |
list_for_resource_group | select | resource_group_name, subscription_id | $filter | Gets deny assignments for a resource group. |
list | select | subscription_id | $filter | Gets all deny assignments for the subscription. |
list_for_scope | select | scope | $filter | Gets deny assignments for a scope. |
get_by_id | select | deny_assignment_id | Gets a deny assignment by ID. | |
create_or_update | insert | scope, deny_assignment_id | Create or update a deny assignment by scope and name. | |
create_or_update | replace | scope, deny_assignment_id | Create or update a deny assignment by scope and name. | |
delete | delete | scope, deny_assignment_id | Delete a deny assignment by scope and name. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
deny_assignment_id | string | The ID of the deny assignment to get. Required. |
parent_resource_path | string | The parent resource identity. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
resource_name | string | The name of the resource to get deny assignments for. Required. |
resource_provider_namespace | string | The namespace of the resource provider. Required. |
resource_type | string | The resource type of the resource. Required. |
scope | string | The fully qualified Azure Resource manager identifier of the resource. Required. |
subscription_id | string | |
$filter | string | The filter to apply on the operation. Use $filter=atScope() to return all deny assignments at or above the scope. Use $filter=denyAssignmentName eq '{name}' to search deny assignments by name at specified scope. Use $filter=principalId eq '{id}' to return all deny assignments at, above and below the scope for the specified principal. Use $filter=gdprExportPrincipalId eq '{id}' to return all deny assignments at, above and below the scope for the specified principal. This filter is different from the principalId filter as it returns not only those deny assignments that contain the specified principal is the Principals list but also those deny assignments that contain the specified principal is the ExcludePrincipals list. Additionally, when gdprExportPrincipalId filter is used, only the deny assignment name and description properties are returned. Default value is None. |
SELECT examples
- list_for_resource
- get
- list_for_resource_group
- list
- list_for_scope
- get_by_id
Gets deny assignments for a resource.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
denyAssignmentEffect,
denyAssignmentName,
description,
doNotApplyToChildScopes,
excludePrincipals,
isSystemProtected,
permissions,
principals,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.deny_assignments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND resource_provider_namespace = '{{ resource_provider_namespace }}' -- required
AND parent_resource_path = '{{ parent_resource_path }}' -- required
AND resource_type = '{{ resource_type }}' -- required
AND resource_name = '{{ resource_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
;
Get the specified deny assignment.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
denyAssignmentEffect,
denyAssignmentName,
description,
doNotApplyToChildScopes,
excludePrincipals,
isSystemProtected,
permissions,
principals,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.deny_assignments
WHERE scope = '{{ scope }}' -- required
AND deny_assignment_id = '{{ deny_assignment_id }}' -- required
;
Gets deny assignments for a resource group.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
denyAssignmentEffect,
denyAssignmentName,
description,
doNotApplyToChildScopes,
excludePrincipals,
isSystemProtected,
permissions,
principals,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.deny_assignments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
;
Gets all deny assignments for the subscription.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
denyAssignmentEffect,
denyAssignmentName,
description,
doNotApplyToChildScopes,
excludePrincipals,
isSystemProtected,
permissions,
principals,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.deny_assignments
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
;
Gets deny assignments for a scope.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
denyAssignmentEffect,
denyAssignmentName,
description,
doNotApplyToChildScopes,
excludePrincipals,
isSystemProtected,
permissions,
principals,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.deny_assignments
WHERE scope = '{{ scope }}' -- required
AND $filter = '{{ $filter }}'
;
Gets a deny assignment by ID.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
denyAssignmentEffect,
denyAssignmentName,
description,
doNotApplyToChildScopes,
excludePrincipals,
isSystemProtected,
permissions,
principals,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.deny_assignments
WHERE deny_assignment_id = '{{ deny_assignment_id }}' -- required
;
INSERT examples
- create_or_update
- Manifest
Create or update a deny assignment by scope and name.
INSERT INTO azure.authorization.deny_assignments (
properties,
scope,
deny_assignment_id
)
SELECT
'{{ properties }}',
'{{ scope }}',
'{{ deny_assignment_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: deny_assignments
props:
- name: scope
value: "{{ scope }}"
description: Required parameter for the deny_assignments resource.
- name: deny_assignment_id
value: "{{ deny_assignment_id }}"
description: Required parameter for the deny_assignments resource.
- name: properties
description: |
Deny assignment properties.
value:
denyAssignmentName: "{{ denyAssignmentName }}"
description: "{{ description }}"
permissions:
- actions: "{{ actions }}"
notActions: "{{ notActions }}"
dataActions: "{{ dataActions }}"
notDataActions: "{{ notDataActions }}"
condition: "{{ condition }}"
conditionVersion: "{{ conditionVersion }}"
scope: "{{ scope }}"
doNotApplyToChildScopes: {{ doNotApplyToChildScopes }}
principals:
- id: "{{ id }}"
type: "{{ type }}"
excludePrincipals:
- id: "{{ id }}"
type: "{{ type }}"
isSystemProtected: {{ isSystemProtected }}
denyAssignmentEffect: "{{ denyAssignmentEffect }}"
condition: "{{ condition }}"
conditionVersion: "{{ conditionVersion }}"
createdOn: "{{ createdOn }}"
updatedOn: "{{ updatedOn }}"
createdBy: "{{ createdBy }}"
updatedBy: "{{ updatedBy }}"
REPLACE examples
- create_or_update
Create or update a deny assignment by scope and name.
REPLACE azure.authorization.deny_assignments
SET
properties = '{{ properties }}'
WHERE
scope = '{{ scope }}' --required
AND deny_assignment_id = '{{ deny_assignment_id }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
DELETE examples
- delete
Delete a deny assignment by scope and name.
DELETE FROM azure.authorization.deny_assignments
WHERE scope = '{{ scope }}' --required
AND deny_assignment_id = '{{ deny_assignment_id }}' --required
;