role_eligibility_schedule_instances
Creates, updates, deletes, gets or lists a role_eligibility_schedule_instances resource.
Overview
| Name | role_eligibility_schedule_instances |
| Type | Resource |
| Id | azure.authorization.role_eligibility_schedule_instances |
Fields
The following fields are returned by SELECT queries:
- get
- list_for_scope
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently accepted value is '2.0'. |
createdOn | string (date-time) | DateTime when role eligibility schedule was created. |
endDateTime | string (date-time) | The endDateTime of the role eligibility schedule instance. |
expandedProperties | object | Additional properties of principal, scope and role definition. |
memberType | string | Membership type of the role eligibility schedule. Known values are: "Inherited", "Direct", and "Group". (Inherited, Direct, Group) |
principalId | string | The principal ID. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. |
roleEligibilityScheduleId | string | Id of the master role eligibility schedule. |
scope | string | The role eligibility schedule scope. |
startDateTime | string (date-time) | The startDateTime of the role eligibility schedule instance. |
status | string | The status of the role eligibility schedule instance. Known values are: "Accepted", "PendingEvaluation", "Granted", "Denied", "PendingProvisioning", "Provisioned", "PendingRevocation", "Revoked", "Canceled", "Failed", "PendingApprovalProvisioning", "PendingApproval", "FailedAsResourceIsLocked", "PendingAdminDecision", "AdminApproved", "AdminDenied", "TimedOut", "ProvisioningStarted", "Invalid", "PendingScheduleCreation", "ScheduleCreated", and "PendingExternalProvisioning". (Accepted, PendingEvaluation, Granted, Denied, PendingProvisioning, Provisioned, PendingRevocation, Revoked, Canceled, Failed, PendingApprovalProvisioning, PendingApproval, FailedAsResourceIsLocked, PendingAdminDecision, AdminApproved, AdminDenied, TimedOut, ProvisioningStarted, Invalid, PendingScheduleCreation, ScheduleCreated, PendingExternalProvisioning) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently accepted value is '2.0'. |
createdOn | string (date-time) | DateTime when role eligibility schedule was created. |
endDateTime | string (date-time) | The endDateTime of the role eligibility schedule instance. |
expandedProperties | object | Additional properties of principal, scope and role definition. |
memberType | string | Membership type of the role eligibility schedule. Known values are: "Inherited", "Direct", and "Group". (Inherited, Direct, Group) |
principalId | string | The principal ID. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. |
roleEligibilityScheduleId | string | Id of the master role eligibility schedule. |
scope | string | The role eligibility schedule scope. |
startDateTime | string (date-time) | The startDateTime of the role eligibility schedule instance. |
status | string | The status of the role eligibility schedule instance. Known values are: "Accepted", "PendingEvaluation", "Granted", "Denied", "PendingProvisioning", "Provisioned", "PendingRevocation", "Revoked", "Canceled", "Failed", "PendingApprovalProvisioning", "PendingApproval", "FailedAsResourceIsLocked", "PendingAdminDecision", "AdminApproved", "AdminDenied", "TimedOut", "ProvisioningStarted", "Invalid", "PendingScheduleCreation", "ScheduleCreated", and "PendingExternalProvisioning". (Accepted, PendingEvaluation, Granted, Denied, PendingProvisioning, Provisioned, PendingRevocation, Revoked, Canceled, Failed, PendingApprovalProvisioning, PendingApproval, FailedAsResourceIsLocked, PendingAdminDecision, AdminApproved, AdminDenied, TimedOut, ProvisioningStarted, Invalid, PendingScheduleCreation, ScheduleCreated, PendingExternalProvisioning) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | scope, role_eligibility_schedule_instance_name | Gets the specified role eligibility schedule instance. | |
list_for_scope | select | scope | $filter | Gets role eligibility schedule instances of a role eligibility schedule. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
role_eligibility_schedule_instance_name | string | The name (hash of schedule name + time) of the role eligibility schedule to get. Required. |
scope | string | The fully qualified Azure Resource manager identifier of the resource. Required. |
$filter | string | The filter to apply on the operation. Use $filter=atScope() to return all role assignment schedules at or above the scope. Use $filter=principalId eq {id} to return all role assignment schedules at, above or below the scope for the specified principal. Use $filter=assignedTo('{userId}') to return all role eligibility schedules for the user. Use $filter=asTarget() to return all role eligibility schedules created for the current user. Default value is None. |
SELECT examples
- get
- list_for_scope
Gets the specified role eligibility schedule instance.
SELECT
id,
name,
condition,
conditionVersion,
createdOn,
endDateTime,
expandedProperties,
memberType,
principalId,
principalType,
roleDefinitionId,
roleEligibilityScheduleId,
scope,
startDateTime,
status,
systemData,
type
FROM azure.authorization.role_eligibility_schedule_instances
WHERE scope = '{{ scope }}' -- required
AND role_eligibility_schedule_instance_name = '{{ role_eligibility_schedule_instance_name }}' -- required
;
Gets role eligibility schedule instances of a role eligibility schedule.
SELECT
id,
name,
condition,
conditionVersion,
createdOn,
endDateTime,
expandedProperties,
memberType,
principalId,
principalType,
roleDefinitionId,
roleEligibilityScheduleId,
scope,
startDateTime,
status,
systemData,
type
FROM azure.authorization.role_eligibility_schedule_instances
WHERE scope = '{{ scope }}' -- required
AND $filter = '{{ $filter }}'
;