Skip to main content

role_assignment_schedule_instances

Creates, updates, deletes, gets or lists a role_assignment_schedule_instances resource.

Overview

Namerole_assignment_schedule_instances
TypeResource
Idazure.authorization.role_assignment_schedule_instances

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringFully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}.
namestringThe name of the resource.
assignmentTypestringAssignment type of the role assignment schedule. Known values are: "Activated" and "Assigned". (Activated, Assigned)
conditionstringThe conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'.
conditionVersionstringVersion of the condition. Currently accepted value is '2.0'.
createdOnstring (date-time)DateTime when role assignment schedule was created.
endDateTimestring (date-time)The endDateTime of the role assignment schedule instance.
expandedPropertiesobjectAdditional properties of principal, scope and role definition.
linkedRoleEligibilityScheduleIdstringroleEligibilityScheduleId used to activate.
linkedRoleEligibilityScheduleInstanceIdstringroleEligibilityScheduleInstanceId linked to this roleAssignmentScheduleInstance.
memberTypestringMembership type of the role assignment schedule. Known values are: "Inherited", "Direct", and "Group". (Inherited, Direct, Group)
originRoleAssignmentIdstringRole Assignment Id in external system.
principalIdstringThe principal ID.
principalTypestringThe principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device)
roleAssignmentScheduleIdstringId of the master role assignment schedule.
roleDefinitionIdstringThe role definition ID.
scopestringThe role assignment schedule scope.
startDateTimestring (date-time)The startDateTime of the role assignment schedule instance.
statusstringThe status of the role assignment schedule instance. Known values are: "Accepted", "PendingEvaluation", "Granted", "Denied", "PendingProvisioning", "Provisioned", "PendingRevocation", "Revoked", "Canceled", "Failed", "PendingApprovalProvisioning", "PendingApproval", "FailedAsResourceIsLocked", "PendingAdminDecision", "AdminApproved", "AdminDenied", "TimedOut", "ProvisioningStarted", "Invalid", "PendingScheduleCreation", "ScheduleCreated", and "PendingExternalProvisioning". (Accepted, PendingEvaluation, Granted, Denied, PendingProvisioning, Provisioned, PendingRevocation, Revoked, Canceled, Failed, PendingApprovalProvisioning, PendingApproval, FailedAsResourceIsLocked, PendingAdminDecision, AdminApproved, AdminDenied, TimedOut, ProvisioningStarted, Invalid, PendingScheduleCreation, ScheduleCreated, PendingExternalProvisioning)
systemDataobjectAzure Resource Manager metadata containing createdBy and modifiedBy information.
typestringThe type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts".

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectscope, role_assignment_schedule_instance_nameGets the specified role assignment schedule instance.
list_for_scopeselectscope$filterGets role assignment schedule instances of a role assignment schedule.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
role_assignment_schedule_instance_namestringThe name (hash of schedule name + time) of the role assignment schedule to get. Required.
scopestringThe fully qualified Azure Resource manager identifier of the resource. Required.
$filterstringThe filter to apply on the operation. Use $filter=atScope() to return all role assignment schedules at or above the scope. Use $filter=principalId eq {id} to return all role assignment schedules at, above or below the scope for the specified principal. Use $filter=assignedTo('{userId}') to return all role assignment schedule instances for the user. Use $filter=asTarget() to return all role assignment schedule instances created for the current user. Default value is None.

SELECT examples

Gets the specified role assignment schedule instance.

SELECT
id,
name,
assignmentType,
condition,
conditionVersion,
createdOn,
endDateTime,
expandedProperties,
linkedRoleEligibilityScheduleId,
linkedRoleEligibilityScheduleInstanceId,
memberType,
originRoleAssignmentId,
principalId,
principalType,
roleAssignmentScheduleId,
roleDefinitionId,
scope,
startDateTime,
status,
systemData,
type
FROM azure.authorization.role_assignment_schedule_instances
WHERE scope = '{{ scope }}' -- required
AND role_assignment_schedule_instance_name = '{{ role_assignment_schedule_instance_name }}' -- required
;