policy_states
Creates, updates, deletes, gets or lists a policy_states resource.
Overview
| Name | policy_states |
| Type | Resource |
| Id | azure.policy_insights.policy_states |
Fields
The following fields are returned by SELECT queries:
- list_query_results_for_resource_group_level_policy_assignment
- list_query_results_for_resource_group
- list_query_results_for_policy_set_definition
- list_query_results_for_policy_definition
- list_query_results_for_subscription_level_policy_assignment
- list_query_results_for_management_group
- list_query_results_for_subscription
- list_query_results_for_resource
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components state compliance records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. This property is deprecated; please use ComplianceState instead. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyAssignmentVersion | string | Evaluated policy assignment version. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionGroupNames | array | Policy definition group names. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policyDefinitionVersion | string | Evaluated policy definition version. |
policyEvaluationDetails | object | Policy evaluation details. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
policySetDefinitionVersion | string | Evaluated policy set definition version. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
timestamp | string (date-time) | Timestamp for the policy state record. |
Methods
The following methods are available for this resource:
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
management_group_name | string | Management group name. Required. |
policy_assignment_name | string | Policy assignment name. Required. |
policy_definition_name | string | Policy definition name. Required. |
policy_set_definition_name | string | Policy set definition name. Required. |
policy_states_resource | string | The virtual resource under PolicyStates resource type. In a given time range, 'latest' represents the latest policy state(s), whereas 'default' represents all policy state(s). Known values are: "default" and "latest". Required. |
policy_states_summary_resource | string | The virtual resource under PolicyStates resource type for summarize action. In a given time range, 'latest' represents the latest policy state(s) and is the only allowed value. "latest" Required. |
resource_group_name | string | Resource group name. Required. |
resource_id | string | Resource ID. Required. |
subscription_id | string | The ID of the target subscription. The value must be an UUID. Required. |
$apply | string | OData apply expression for aggregations. Default value is None. |
$expand | string | The $expand query parameter. For example, to expand components use $expand=components. Default value is None. |
$filter | string | OData filter expression. Default value is None. |
$from | string (date-time) | ISO 8601 formatted timestamp specifying the start time of the interval to query. When not specified, the service uses ($to - 1-day). Default value is None. |
$orderby | string | Ordering expression using OData notation. One or more comma-separated column names with an optional "desc" (the default) or "asc", e.g. "$orderby=PolicyAssignmentId, ResourceId asc". Default value is None. |
$select | string | Select expression using OData notation. Limits the columns on each record to just those requested, e.g. "$select=PolicyAssignmentId, ResourceId". Default value is None. |
$skiptoken | string | Skiptoken is only provided if a previous response returned a partial result as a part of nextLink element. Default value is None. |
$to | string (date-time) | ISO 8601 formatted timestamp specifying the end time of the interval to query. When not specified, the service uses request time. Default value is None. |
$top | integer | Maximum number of records to return. Default value is None. |
SELECT examples
- list_query_results_for_resource_group_level_policy_assignment
- list_query_results_for_resource_group
- list_query_results_for_policy_set_definition
- list_query_results_for_policy_definition
- list_query_results_for_subscription_level_policy_assignment
- list_query_results_for_management_group
- list_query_results_for_subscription
- list_query_results_for_resource
Queries policy states for the resource group level policy assignment.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE subscription_id = '{{ subscription_id }}' -- required
AND resource_group_name = '{{ resource_group_name }}' -- required
AND policy_states_resource = '{{ policy_states_resource }}' -- required
AND policy_assignment_name = '{{ policy_assignment_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the resources under the resource group.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE subscription_id = '{{ subscription_id }}' -- required
AND resource_group_name = '{{ resource_group_name }}' -- required
AND policy_states_resource = '{{ policy_states_resource }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the subscription level policy set definition.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_states_resource = '{{ policy_states_resource }}' -- required
AND policy_set_definition_name = '{{ policy_set_definition_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the subscription level policy definition.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_states_resource = '{{ policy_states_resource }}' -- required
AND policy_definition_name = '{{ policy_definition_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the subscription level policy assignment.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_states_resource = '{{ policy_states_resource }}' -- required
AND policy_assignment_name = '{{ policy_assignment_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the resources under the management group.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE policy_states_resource = '{{ policy_states_resource }}' -- required
AND management_group_name = '{{ management_group_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the resources under the subscription.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_states_resource = '{{ policy_states_resource }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy states for the resource.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyAssignmentVersion,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionGroupNames,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policyDefinitionVersion,
policyEvaluationDetails,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
policySetDefinitionVersion,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
timestamp
FROM azure.policy_insights.policy_states
WHERE policy_states_resource = '{{ policy_states_resource }}' -- required
AND resource_id = '{{ resource_id }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $expand = '{{ $expand }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Lifecycle Methods
- summarize_for_management_group
- summarize_for_subscription
- summarize_for_resource_group
- summarize_for_resource
- trigger_subscription_evaluation
- trigger_resource_group_evaluation
- summarize_for_policy_set_definition
- summarize_for_policy_definition
- summarize_for_subscription_level_policy_assignment
- summarize_for_resource_group_level_policy_assignment
Summarizes policy states for the resources under the management group.
EXEC azure.policy_insights.policy_states.summarize_for_management_group
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@management_group_name='{{ management_group_name }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Summarizes policy states for the resources under the subscription.
EXEC azure.policy_insights.policy_states.summarize_for_subscription
@subscription_id='{{ subscription_id }}' --required,
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Summarizes policy states for the resources under the resource group.
EXEC azure.policy_insights.policy_states.summarize_for_resource_group
@subscription_id='{{ subscription_id }}' --required,
@resource_group_name='{{ resource_group_name }}' --required,
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Summarizes policy states for the resource.
EXEC azure.policy_insights.policy_states.summarize_for_resource
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@resource_id='{{ resource_id }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Triggers a policy evaluation scan for all the resources under the subscription.
EXEC azure.policy_insights.policy_states.trigger_subscription_evaluation
@subscription_id='{{ subscription_id }}' --required
;
Triggers a policy evaluation scan for all the resources under the resource group.
EXEC azure.policy_insights.policy_states.trigger_resource_group_evaluation
@subscription_id='{{ subscription_id }}' --required,
@resource_group_name='{{ resource_group_name }}' --required
;
Summarizes policy states for the subscription level policy set definition.
EXEC azure.policy_insights.policy_states.summarize_for_policy_set_definition
@subscription_id='{{ subscription_id }}' --required,
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@policy_set_definition_name='{{ policy_set_definition_name }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Summarizes policy states for the subscription level policy definition.
EXEC azure.policy_insights.policy_states.summarize_for_policy_definition
@subscription_id='{{ subscription_id }}' --required,
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@policy_definition_name='{{ policy_definition_name }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Summarizes policy states for the subscription level policy assignment.
EXEC azure.policy_insights.policy_states.summarize_for_subscription_level_policy_assignment
@subscription_id='{{ subscription_id }}' --required,
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@policy_assignment_name='{{ policy_assignment_name }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;
Summarizes policy states for the resource group level policy assignment.
EXEC azure.policy_insights.policy_states.summarize_for_resource_group_level_policy_assignment
@subscription_id='{{ subscription_id }}' --required,
@resource_group_name='{{ resource_group_name }}' --required,
@policy_states_summary_resource='{{ policy_states_summary_resource }}' --required,
@policy_assignment_name='{{ policy_assignment_name }}' --required,
@$top='{{ $top }}',
@$from='{{ $from }}',
@$to='{{ $to }}',
@$filter='{{ $filter }}'
;