Skip to main content

role_assignment_schedules

Creates, updates, deletes, gets or lists a role_assignment_schedules resource.

Overview

Namerole_assignment_schedules
TypeResource
Idazure.authorization.role_assignment_schedules

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringFully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}.
namestringThe name of the resource.
assignmentTypestringAssignment type of the role assignment schedule. Known values are: "Activated" and "Assigned". (Activated, Assigned)
conditionstringThe conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'.
conditionVersionstringVersion of the condition. Currently accepted value is '2.0'.
createdOnstring (date-time)DateTime when role assignment schedule was created.
endDateTimestring (date-time)End DateTime when role assignment schedule.
expandedPropertiesobjectAdditional properties of principal, scope and role definition.
linkedRoleEligibilityScheduleIdstringThe id of roleEligibilitySchedule used to activated this roleAssignmentSchedule.
memberTypestringMembership type of the role assignment schedule. Known values are: "Inherited", "Direct", and "Group". (Inherited, Direct, Group)
principalIdstringThe principal ID.
principalTypestringThe principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device)
roleAssignmentScheduleRequestIdstringThe id of roleAssignmentScheduleRequest used to create this roleAssignmentSchedule.
roleDefinitionIdstringThe role definition ID.
scopestringThe role assignment schedule scope.
startDateTimestring (date-time)Start DateTime when role assignment schedule.
statusstringThe status of the role assignment schedule. Known values are: "Accepted", "PendingEvaluation", "Granted", "Denied", "PendingProvisioning", "Provisioned", "PendingRevocation", "Revoked", "Canceled", "Failed", "PendingApprovalProvisioning", "PendingApproval", "FailedAsResourceIsLocked", "PendingAdminDecision", "AdminApproved", "AdminDenied", "TimedOut", "ProvisioningStarted", "Invalid", "PendingScheduleCreation", "ScheduleCreated", and "PendingExternalProvisioning". (Accepted, PendingEvaluation, Granted, Denied, PendingProvisioning, Provisioned, PendingRevocation, Revoked, Canceled, Failed, PendingApprovalProvisioning, PendingApproval, FailedAsResourceIsLocked, PendingAdminDecision, AdminApproved, AdminDenied, TimedOut, ProvisioningStarted, Invalid, PendingScheduleCreation, ScheduleCreated, PendingExternalProvisioning)
systemDataobjectAzure Resource Manager metadata containing createdBy and modifiedBy information.
typestringThe type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts".
updatedOnstring (date-time)DateTime when role assignment schedule was modified.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectscope, role_assignment_schedule_nameGet the specified role assignment schedule for a resource scope.
list_for_scopeselectscope$filterGets role assignment schedules for a resource scope.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
role_assignment_schedule_namestringThe name (guid) of the role assignment schedule to get. Required.
scopestringThe fully qualified Azure Resource manager identifier of the resource. Required.
$filterstringThe filter to apply on the operation. Use $filter=atScope() to return all role assignment schedules at or above the scope. Use $filter=principalId eq {id} to return all role assignment schedules at, above or below the scope for the specified principal. Use $filter=assignedTo('{userId}') to return all role assignment schedules for the current user. Use $filter=asTarget() to return all role assignment schedules created for the current user. Default value is None.

SELECT examples

Get the specified role assignment schedule for a resource scope.

SELECT
id,
name,
assignmentType,
condition,
conditionVersion,
createdOn,
endDateTime,
expandedProperties,
linkedRoleEligibilityScheduleId,
memberType,
principalId,
principalType,
roleAssignmentScheduleRequestId,
roleDefinitionId,
scope,
startDateTime,
status,
systemData,
type,
updatedOn
FROM azure.authorization.role_assignment_schedules
WHERE scope = '{{ scope }}' -- required
AND role_assignment_schedule_name = '{{ role_assignment_schedule_name }}' -- required
;