user_assigned_identities
Creates, updates, deletes, gets or lists a user_assigned_identities resource.
Overview
| Name | user_assigned_identities |
| Type | Resource |
| Id | azure.msi.user_assigned_identities |
Fields
The following fields are returned by SELECT queries:
- get
- list_by_resource_group
- list_by_subscription
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentRestrictions | object | Restrictions on which resource providers this identity can be assigned to. |
clientId | string | The id of the app associated with the identity. This is a random generated UUID by MSI. |
isolationScope | string | Enum to configure regional restrictions on identity assignment, as necessary. Known values are: "None" and "Regional". (None, Regional) |
location | string | The geo-location where the resource lives. Required. |
principalId | string | The id of the service principal object associated with the created identity. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
tenantId | string | The id of the tenant which the identity belongs to. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentRestrictions | object | Restrictions on which resource providers this identity can be assigned to. |
clientId | string | The id of the app associated with the identity. This is a random generated UUID by MSI. |
isolationScope | string | Enum to configure regional restrictions on identity assignment, as necessary. Known values are: "None" and "Regional". (None, Regional) |
location | string | The geo-location where the resource lives. Required. |
principalId | string | The id of the service principal object associated with the created identity. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
tenantId | string | The id of the tenant which the identity belongs to. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentRestrictions | object | Restrictions on which resource providers this identity can be assigned to. |
clientId | string | The id of the app associated with the identity. This is a random generated UUID by MSI. |
isolationScope | string | Enum to configure regional restrictions on identity assignment, as necessary. Known values are: "None" and "Regional". (None, Regional) |
location | string | The geo-location where the resource lives. Required. |
principalId | string | The id of the service principal object associated with the created identity. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
tenantId | string | The id of the tenant which the identity belongs to. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | resource_group_name, resource_name, subscription_id | Gets the identity. | |
list_by_resource_group | select | resource_group_name, subscription_id | Lists all the userAssignedIdentities available under the specified ResourceGroup. | |
list_by_subscription | select | subscription_id | Lists all the userAssignedIdentities available under the specified subscription. | |
create_or_update | insert | resource_group_name, resource_name, subscription_id, location | Create or update an identity in the specified subscription and resource group. | |
update | update | resource_group_name, resource_name, subscription_id | Update an identity in the specified subscription and resource group. | |
create_or_update | replace | resource_group_name, resource_name, subscription_id, location | Create or update an identity in the specified subscription and resource group. | |
delete | delete | resource_group_name, resource_name, subscription_id | Deletes the identity. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
resource_name | string | The name of the identity resource. Required. |
subscription_id | string |
SELECT examples
- get
- list_by_resource_group
- list_by_subscription
Gets the identity.
SELECT
id,
name,
assignmentRestrictions,
clientId,
isolationScope,
location,
principalId,
systemData,
tags,
tenantId,
type
FROM azure.msi.user_assigned_identities
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND resource_name = '{{ resource_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Lists all the userAssignedIdentities available under the specified ResourceGroup.
SELECT
id,
name,
assignmentRestrictions,
clientId,
isolationScope,
location,
principalId,
systemData,
tags,
tenantId,
type
FROM azure.msi.user_assigned_identities
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Lists all the userAssignedIdentities available under the specified subscription.
SELECT
id,
name,
assignmentRestrictions,
clientId,
isolationScope,
location,
principalId,
systemData,
tags,
tenantId,
type
FROM azure.msi.user_assigned_identities
WHERE subscription_id = '{{ subscription_id }}' -- required
;
INSERT examples
- create_or_update
- Manifest
Create or update an identity in the specified subscription and resource group.
INSERT INTO azure.msi.user_assigned_identities (
tags,
location,
properties,
resource_group_name,
resource_name,
subscription_id
)
SELECT
'{{ tags }}',
'{{ location }}' /* required */,
'{{ properties }}',
'{{ resource_group_name }}',
'{{ resource_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
location,
properties,
systemData,
tags,
type
;
# Description fields are for documentation purposes
- name: user_assigned_identities
props:
- name: resource_group_name
value: "{{ resource_group_name }}"
description: Required parameter for the user_assigned_identities resource.
- name: resource_name
value: "{{ resource_name }}"
description: Required parameter for the user_assigned_identities resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the user_assigned_identities resource.
- name: tags
value: "{{ tags }}"
description: |
Resource tags.
- name: location
value: "{{ location }}"
description: |
The geo-location where the resource lives. Required.
- name: properties
description: |
The properties associated with the identity.
value:
tenantId: "{{ tenantId }}"
principalId: "{{ principalId }}"
clientId: "{{ clientId }}"
isolationScope: "{{ isolationScope }}"
assignmentRestrictions:
providers:
- "{{ providers }}"
UPDATE examples
- update
Update an identity in the specified subscription and resource group.
UPDATE azure.msi.user_assigned_identities
SET
location = '{{ location }}',
tags = '{{ tags }}',
properties = '{{ properties }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND resource_name = '{{ resource_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
location,
properties,
systemData,
tags,
type;
REPLACE examples
- create_or_update
Create or update an identity in the specified subscription and resource group.
REPLACE azure.msi.user_assigned_identities
SET
tags = '{{ tags }}',
location = '{{ location }}',
properties = '{{ properties }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND resource_name = '{{ resource_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND location = '{{ location }}' --required
RETURNING
id,
name,
location,
properties,
systemData,
tags,
type;
DELETE examples
- delete
Deletes the identity.
DELETE FROM azure.msi.user_assigned_identities
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND resource_name = '{{ resource_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;