policy_assignments
Creates, updates, deletes, gets or lists a policy_assignments resource.
Overview
| Name | policy_assignments |
| Type | Resource |
| Id | azure.resource.policy_assignments |
Fields
The following fields are returned by SELECT queries:
- list_for_resource
- get
- list_for_resource_group
- list
- list_for_management_group
- get_by_id
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentType | string | The type of policy assignment. Possible values are NotSpecified, System, SystemHidden, and Custom. Immutable. Known values are: "NotSpecified", "System", "SystemHidden", and "Custom". (NotSpecified, System, SystemHidden, Custom) |
definitionVersion | string | The version of the policy definition to use. |
description | string | This message will be part of response in case of policy violation. |
displayName | string | The display name of the policy assignment. |
effectiveDefinitionVersion | string | The effective version of the policy definition in use. This is only present if requested via the $expand query parameter. |
enforcementMode | string | The policy assignment enforcement mode. Possible values are Default, DoNotEnforce, and Enroll. Known values are: "Default", "DoNotEnforce", and "Enroll". (Default, DoNotEnforce, Enroll) |
identity | object | The managed identity associated with the policy assignment. |
instanceId | string | The instance ID of the policy assignment. This ID only and always changes when the assignment is deleted and recreated. |
latestDefinitionVersion | string | The latest version of the policy definition available. This is only present if requested via the $expand query parameter. |
location | string | The location of the policy assignment. Only required when utilizing managed identity. |
metadata | object | The policy assignment metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
nonComplianceMessages | array | The messages that describe why a resource is non-compliant with the policy. |
notScopes | array | The policy's excluded scopes. |
overrides | array | The policy property value override. |
parameters | object | The parameter values for the assigned policy rule. The keys are the parameter names. |
policyDefinitionId | string | The ID of the policy definition or policy set definition being assigned. |
resourceSelectors | array | The resource selector list to filter policies by resource properties. |
scope | string | The scope for the policy assignment. |
selfServeExemptionSettings | object | The self-serve exemption settings for the policy assignment. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentType | string | The type of policy assignment. Possible values are NotSpecified, System, SystemHidden, and Custom. Immutable. Known values are: "NotSpecified", "System", "SystemHidden", and "Custom". (NotSpecified, System, SystemHidden, Custom) |
definitionVersion | string | The version of the policy definition to use. |
description | string | This message will be part of response in case of policy violation. |
displayName | string | The display name of the policy assignment. |
effectiveDefinitionVersion | string | The effective version of the policy definition in use. This is only present if requested via the $expand query parameter. |
enforcementMode | string | The policy assignment enforcement mode. Possible values are Default, DoNotEnforce, and Enroll. Known values are: "Default", "DoNotEnforce", and "Enroll". (Default, DoNotEnforce, Enroll) |
identity | object | The managed identity associated with the policy assignment. |
instanceId | string | The instance ID of the policy assignment. This ID only and always changes when the assignment is deleted and recreated. |
latestDefinitionVersion | string | The latest version of the policy definition available. This is only present if requested via the $expand query parameter. |
location | string | The location of the policy assignment. Only required when utilizing managed identity. |
metadata | object | The policy assignment metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
nonComplianceMessages | array | The messages that describe why a resource is non-compliant with the policy. |
notScopes | array | The policy's excluded scopes. |
overrides | array | The policy property value override. |
parameters | object | The parameter values for the assigned policy rule. The keys are the parameter names. |
policyDefinitionId | string | The ID of the policy definition or policy set definition being assigned. |
resourceSelectors | array | The resource selector list to filter policies by resource properties. |
scope | string | The scope for the policy assignment. |
selfServeExemptionSettings | object | The self-serve exemption settings for the policy assignment. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentType | string | The type of policy assignment. Possible values are NotSpecified, System, SystemHidden, and Custom. Immutable. Known values are: "NotSpecified", "System", "SystemHidden", and "Custom". (NotSpecified, System, SystemHidden, Custom) |
definitionVersion | string | The version of the policy definition to use. |
description | string | This message will be part of response in case of policy violation. |
displayName | string | The display name of the policy assignment. |
effectiveDefinitionVersion | string | The effective version of the policy definition in use. This is only present if requested via the $expand query parameter. |
enforcementMode | string | The policy assignment enforcement mode. Possible values are Default, DoNotEnforce, and Enroll. Known values are: "Default", "DoNotEnforce", and "Enroll". (Default, DoNotEnforce, Enroll) |
identity | object | The managed identity associated with the policy assignment. |
instanceId | string | The instance ID of the policy assignment. This ID only and always changes when the assignment is deleted and recreated. |
latestDefinitionVersion | string | The latest version of the policy definition available. This is only present if requested via the $expand query parameter. |
location | string | The location of the policy assignment. Only required when utilizing managed identity. |
metadata | object | The policy assignment metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
nonComplianceMessages | array | The messages that describe why a resource is non-compliant with the policy. |
notScopes | array | The policy's excluded scopes. |
overrides | array | The policy property value override. |
parameters | object | The parameter values for the assigned policy rule. The keys are the parameter names. |
policyDefinitionId | string | The ID of the policy definition or policy set definition being assigned. |
resourceSelectors | array | The resource selector list to filter policies by resource properties. |
scope | string | The scope for the policy assignment. |
selfServeExemptionSettings | object | The self-serve exemption settings for the policy assignment. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentType | string | The type of policy assignment. Possible values are NotSpecified, System, SystemHidden, and Custom. Immutable. Known values are: "NotSpecified", "System", "SystemHidden", and "Custom". (NotSpecified, System, SystemHidden, Custom) |
definitionVersion | string | The version of the policy definition to use. |
description | string | This message will be part of response in case of policy violation. |
displayName | string | The display name of the policy assignment. |
effectiveDefinitionVersion | string | The effective version of the policy definition in use. This is only present if requested via the $expand query parameter. |
enforcementMode | string | The policy assignment enforcement mode. Possible values are Default, DoNotEnforce, and Enroll. Known values are: "Default", "DoNotEnforce", and "Enroll". (Default, DoNotEnforce, Enroll) |
identity | object | The managed identity associated with the policy assignment. |
instanceId | string | The instance ID of the policy assignment. This ID only and always changes when the assignment is deleted and recreated. |
latestDefinitionVersion | string | The latest version of the policy definition available. This is only present if requested via the $expand query parameter. |
location | string | The location of the policy assignment. Only required when utilizing managed identity. |
metadata | object | The policy assignment metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
nonComplianceMessages | array | The messages that describe why a resource is non-compliant with the policy. |
notScopes | array | The policy's excluded scopes. |
overrides | array | The policy property value override. |
parameters | object | The parameter values for the assigned policy rule. The keys are the parameter names. |
policyDefinitionId | string | The ID of the policy definition or policy set definition being assigned. |
resourceSelectors | array | The resource selector list to filter policies by resource properties. |
scope | string | The scope for the policy assignment. |
selfServeExemptionSettings | object | The self-serve exemption settings for the policy assignment. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentType | string | The type of policy assignment. Possible values are NotSpecified, System, SystemHidden, and Custom. Immutable. Known values are: "NotSpecified", "System", "SystemHidden", and "Custom". (NotSpecified, System, SystemHidden, Custom) |
definitionVersion | string | The version of the policy definition to use. |
description | string | This message will be part of response in case of policy violation. |
displayName | string | The display name of the policy assignment. |
effectiveDefinitionVersion | string | The effective version of the policy definition in use. This is only present if requested via the $expand query parameter. |
enforcementMode | string | The policy assignment enforcement mode. Possible values are Default, DoNotEnforce, and Enroll. Known values are: "Default", "DoNotEnforce", and "Enroll". (Default, DoNotEnforce, Enroll) |
identity | object | The managed identity associated with the policy assignment. |
instanceId | string | The instance ID of the policy assignment. This ID only and always changes when the assignment is deleted and recreated. |
latestDefinitionVersion | string | The latest version of the policy definition available. This is only present if requested via the $expand query parameter. |
location | string | The location of the policy assignment. Only required when utilizing managed identity. |
metadata | object | The policy assignment metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
nonComplianceMessages | array | The messages that describe why a resource is non-compliant with the policy. |
notScopes | array | The policy's excluded scopes. |
overrides | array | The policy property value override. |
parameters | object | The parameter values for the assigned policy rule. The keys are the parameter names. |
policyDefinitionId | string | The ID of the policy definition or policy set definition being assigned. |
resourceSelectors | array | The resource selector list to filter policies by resource properties. |
scope | string | The scope for the policy assignment. |
selfServeExemptionSettings | object | The self-serve exemption settings for the policy assignment. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assignmentType | string | The type of policy assignment. Possible values are NotSpecified, System, SystemHidden, and Custom. Immutable. Known values are: "NotSpecified", "System", "SystemHidden", and "Custom". (NotSpecified, System, SystemHidden, Custom) |
definitionVersion | string | The version of the policy definition to use. |
description | string | This message will be part of response in case of policy violation. |
displayName | string | The display name of the policy assignment. |
effectiveDefinitionVersion | string | The effective version of the policy definition in use. This is only present if requested via the $expand query parameter. |
enforcementMode | string | The policy assignment enforcement mode. Possible values are Default, DoNotEnforce, and Enroll. Known values are: "Default", "DoNotEnforce", and "Enroll". (Default, DoNotEnforce, Enroll) |
identity | object | The managed identity associated with the policy assignment. |
instanceId | string | The instance ID of the policy assignment. This ID only and always changes when the assignment is deleted and recreated. |
latestDefinitionVersion | string | The latest version of the policy definition available. This is only present if requested via the $expand query parameter. |
location | string | The location of the policy assignment. Only required when utilizing managed identity. |
metadata | object | The policy assignment metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
nonComplianceMessages | array | The messages that describe why a resource is non-compliant with the policy. |
notScopes | array | The policy's excluded scopes. |
overrides | array | The policy property value override. |
parameters | object | The parameter values for the assigned policy rule. The keys are the parameter names. |
policyDefinitionId | string | The ID of the policy definition or policy set definition being assigned. |
resourceSelectors | array | The resource selector list to filter policies by resource properties. |
scope | string | The scope for the policy assignment. |
selfServeExemptionSettings | object | The self-serve exemption settings for the policy assignment. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list_for_resource | select | resource_group_name, resource_provider_namespace, parent_resource_path, resource_type, resource_name, subscription_id | $filter, $expand, $top | Retrieves all policy assignments that apply to a resource. This operation retrieves the list of all policy assignments associated with the specified resource in the given resource group and subscription that match the optional given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, the unfiltered list includes all policy assignments associated with the resource, including those that apply directly or from all containing scopes, as well as any applied to resources contained within the resource. If $filter=atScope() is provided, the returned list includes all policy assignments that apply to the resource, which is everything in the unfiltered list except those applied to resources contained within the resource. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the resource level. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value} that apply to the resource. Three parameters plus the resource name are used to identify a specific resource. If the resource is not part of a parent resource (the more common case), the parent resource path should not be provided (or provided as ''). For example a web app could be specified as ({resourceProviderNamespace} == 'Microsoft.Web', {parentResourcePath} == '', {resourceType} == 'sites', {resourceName} == 'MyWebApp'). If the resource is part of a parent resource, then all parameters should be provided. For example a virtual machine DNS name could be specified as ({resourceProviderNamespace} == 'Microsoft.Compute', {parentResourcePath} == 'virtualMachines/MyVirtualMachine', {resourceType} == 'domainNames', {resourceName} == 'MyComputerName'). A convenient alternative to providing the namespace and type name separately is to provide both in the {resourceType} parameter, format: ({resourceProviderNamespace} == '', {parentResourcePath} == '', {resourceType} == 'Microsoft.Web/sites', {resourceName} == 'MyWebApp'). |
get | select | scope, policy_assignment_name | $expand | This operation retrieves a single policy assignment, given its name and the scope it was created at. |
list_for_resource_group | select | resource_group_name, subscription_id | $filter, $expand, $top | This operation retrieves the list of all policy assignments associated with the given resource group in the given subscription that match the optional given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, the unfiltered list includes all policy assignments associated with the resource group, including those that apply directly or apply from containing scopes, as well as any applied to resources contained within the resource group. If $filter=atScope() is provided, the returned list includes all policy assignments that apply to the resource group, which is everything in the unfiltered list except those applied to resources contained within the resource group. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the resource group. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value} that apply to the resource group. |
list | select | subscription_id | $filter, $expand, $top | Retrieves all policy assignments that apply to a subscription. This operation retrieves the list of all policy assignments associated with the given subscription that match the optional given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, the unfiltered list includes all policy assignments associated with the subscription, including those that apply directly or from management groups that contain the given subscription, as well as any applied to objects contained within the subscription. If $filter=atScope() is provided, the returned list includes all policy assignments that apply to the subscription, which is everything in the unfiltered list except those applied to objects contained within the subscription. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the subscription. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value}. |
list_for_management_group | select | management_group_id | $filter, $expand, $top | Retrieves all policy assignments that apply to a management group. This operation retrieves the list of all policy assignments applicable to the management group that match the given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter=atScope() is provided, the returned list includes all policy assignments that are assigned to the management group or the management group's ancestors. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the management group. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value} that apply to the management group. |
get_by_id | select | policy_assignment_id | Retrieves the policy assignment with the given ID. The operation retrieves the policy assignment with the given ID. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid scopes are: management group (format: '/providers/Microsoft.Management/managementGroups/{managementGroup}'), subscription (format: '/subscriptions/{subscriptionId}'), resource group (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}', or resource (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}'. | |
create | insert | scope, policy_assignment_name | This operation creates or updates a policy assignment with the given scope and name. Policy assignments apply to all resources contained within their scope. For example, when you assign a policy at resource group scope, that policy applies to all resources in the group. | |
create_by_id | insert | policy_assignment_id | Creates or updates a policy assignment. This operation creates or updates the policy assignment with the given ID. Policy assignments made on a scope apply to all resources contained in that scope. For example, when you assign a policy to a resource group that policy applies to all resources in the group. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid scopes are: management group (format: '/providers/Microsoft.Management/managementGroups/{managementGroup}'), subscription (format: '/subscriptions/{subscriptionId}'), resource group (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}', or resource (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}'. | |
update | update | scope, policy_assignment_name | This operation updates a policy assignment with the given scope and name. Policy assignments apply to all resources contained within their scope. For example, when you assign a policy at resource group scope, that policy applies to all resources in the group. | |
update_by_id | update | policy_assignment_id | Updates a policy assignment. This operation updates the policy assignment with the given ID. Policy assignments made on a scope apply to all resources contained in that scope. For example, when you assign a policy to a resource group that policy applies to all resources in the group. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid scopes are: management group (format: '/providers/Microsoft.Management/managementGroups/{managementGroup}'), subscription (format: '/subscriptions/{subscriptionId}'), resource group (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}', or resource (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}'. | |
delete | delete | scope, policy_assignment_name | This operation deletes a policy assignment, given its name and the scope it was created in. The scope of a policy assignment is the part of its ID preceding '/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. | |
delete_by_id | delete | policy_assignment_id | Deletes a policy assignment. This operation deletes the policy with the given ID. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid formats for {scope} are: '/providers/Microsoft.Management/managementGroups/{managementGroup}' (management group), '/subscriptions/{subscriptionId}' (subscription), '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}' (resource group), or '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}' (resource). |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
management_group_id | string | The management group ID. Required. |
parent_resource_path | string | The parent resource path. Use empty string if there is none. Required. |
policy_assignment_id | string | The ID of the policy assignment to get. Use the format '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Required. |
policy_assignment_name | string | The name of the policy assignment to get. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
resource_name | string | The name of the resource. Required. |
resource_provider_namespace | string | The namespace of the resource provider. For example, the namespace of a virtual machine is Microsoft.Compute (from Microsoft.Compute/virtualMachines). Required. |
resource_type | string | The resource type name. For example the type name of a web app is 'sites' (from Microsoft.Web/sites). Required. |
scope | string | The fully qualified Azure Resource manager identifier of the resource. Required. |
subscription_id | string | |
$expand | string | Comma-separated list of additional properties to be included in the response. Supported values are 'LatestDefinitionVersion, EffectiveDefinitionVersion'. Default value is None. |
$filter | string | The filter to apply on the operation. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, no filtering is performed. If $filter=atScope() is provided, the returned list only includes all policy assignments that apply to the scope, which is everything in the unfiltered list except those applied to sub scopes contained within the given scope. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the given scope. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value}. Default value is None. |
$top | integer | Maximum number of records to return. When the $top filter is not provided, it will return 500 records. Default value is None. |
SELECT examples
- list_for_resource
- get
- list_for_resource_group
- list
- list_for_management_group
- get_by_id
Retrieves all policy assignments that apply to a resource. This operation retrieves the list of all policy assignments associated with the specified resource in the given resource group and subscription that match the optional given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, the unfiltered list includes all policy assignments associated with the resource, including those that apply directly or from all containing scopes, as well as any applied to resources contained within the resource. If $filter=atScope() is provided, the returned list includes all policy assignments that apply to the resource, which is everything in the unfiltered list except those applied to resources contained within the resource. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the resource level. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value} that apply to the resource. Three parameters plus the resource name are used to identify a specific resource. If the resource is not part of a parent resource (the more common case), the parent resource path should not be provided (or provided as ''). For example a web app could be specified as ({resourceProviderNamespace} == 'Microsoft.Web', {parentResourcePath} == '', {resourceType} == 'sites', {resourceName} == 'MyWebApp'). If the resource is part of a parent resource, then all parameters should be provided. For example a virtual machine DNS name could be specified as ({resourceProviderNamespace} == 'Microsoft.Compute', {parentResourcePath} == 'virtualMachines/MyVirtualMachine', {resourceType} == 'domainNames', {resourceName} == 'MyComputerName'). A convenient alternative to providing the namespace and type name separately is to provide both in the {resourceType} parameter, format: ({resourceProviderNamespace} == '', {parentResourcePath} == '', {resourceType} == 'Microsoft.Web/sites', {resourceName} == 'MyWebApp').
SELECT
id,
name,
assignmentType,
definitionVersion,
description,
displayName,
effectiveDefinitionVersion,
enforcementMode,
identity,
instanceId,
latestDefinitionVersion,
location,
metadata,
nonComplianceMessages,
notScopes,
overrides,
parameters,
policyDefinitionId,
resourceSelectors,
scope,
selfServeExemptionSettings,
systemData,
type
FROM azure.resource.policy_assignments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND resource_provider_namespace = '{{ resource_provider_namespace }}' -- required
AND parent_resource_path = '{{ parent_resource_path }}' -- required
AND resource_type = '{{ resource_type }}' -- required
AND resource_name = '{{ resource_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
This operation retrieves a single policy assignment, given its name and the scope it was created at.
SELECT
id,
name,
assignmentType,
definitionVersion,
description,
displayName,
effectiveDefinitionVersion,
enforcementMode,
identity,
instanceId,
latestDefinitionVersion,
location,
metadata,
nonComplianceMessages,
notScopes,
overrides,
parameters,
policyDefinitionId,
resourceSelectors,
scope,
selfServeExemptionSettings,
systemData,
type
FROM azure.resource.policy_assignments
WHERE scope = '{{ scope }}' -- required
AND policy_assignment_name = '{{ policy_assignment_name }}' -- required
AND $expand = '{{ $expand }}'
;
This operation retrieves the list of all policy assignments associated with the given resource group in the given subscription that match the optional given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, the unfiltered list includes all policy assignments associated with the resource group, including those that apply directly or apply from containing scopes, as well as any applied to resources contained within the resource group. If $filter=atScope() is provided, the returned list includes all policy assignments that apply to the resource group, which is everything in the unfiltered list except those applied to resources contained within the resource group. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the resource group. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value} that apply to the resource group.
SELECT
id,
name,
assignmentType,
definitionVersion,
description,
displayName,
effectiveDefinitionVersion,
enforcementMode,
identity,
instanceId,
latestDefinitionVersion,
location,
metadata,
nonComplianceMessages,
notScopes,
overrides,
parameters,
policyDefinitionId,
resourceSelectors,
scope,
selfServeExemptionSettings,
systemData,
type
FROM azure.resource.policy_assignments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
Retrieves all policy assignments that apply to a subscription. This operation retrieves the list of all policy assignments associated with the given subscription that match the optional given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter is not provided, the unfiltered list includes all policy assignments associated with the subscription, including those that apply directly or from management groups that contain the given subscription, as well as any applied to objects contained within the subscription. If $filter=atScope() is provided, the returned list includes all policy assignments that apply to the subscription, which is everything in the unfiltered list except those applied to objects contained within the subscription. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the subscription. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value}.
SELECT
id,
name,
assignmentType,
definitionVersion,
description,
displayName,
effectiveDefinitionVersion,
enforcementMode,
identity,
instanceId,
latestDefinitionVersion,
location,
metadata,
nonComplianceMessages,
notScopes,
overrides,
parameters,
policyDefinitionId,
resourceSelectors,
scope,
selfServeExemptionSettings,
systemData,
type
FROM azure.resource.policy_assignments
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
Retrieves all policy assignments that apply to a management group. This operation retrieves the list of all policy assignments applicable to the management group that match the given $filter. Valid values for $filter are: 'atScope()', 'atExactScope()' or 'policyDefinitionId eq '{value}''. If $filter=atScope() is provided, the returned list includes all policy assignments that are assigned to the management group or the management group's ancestors. If $filter=atExactScope() is provided, the returned list only includes all policy assignments that at the management group. If $filter=policyDefinitionId eq '{value}' is provided, the returned list includes all policy assignments of the policy definition whose id is {value} that apply to the management group.
SELECT
id,
name,
assignmentType,
definitionVersion,
description,
displayName,
effectiveDefinitionVersion,
enforcementMode,
identity,
instanceId,
latestDefinitionVersion,
location,
metadata,
nonComplianceMessages,
notScopes,
overrides,
parameters,
policyDefinitionId,
resourceSelectors,
scope,
selfServeExemptionSettings,
systemData,
type
FROM azure.resource.policy_assignments
WHERE management_group_id = '{{ management_group_id }}' -- required
AND $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
Retrieves the policy assignment with the given ID. The operation retrieves the policy assignment with the given ID. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid scopes are: management group (format: '/providers/Microsoft.Management/managementGroups/{managementGroup}'), subscription (format: '/subscriptions/{subscriptionId}'), resource group (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}', or resource (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}'.
SELECT
id,
name,
assignmentType,
definitionVersion,
description,
displayName,
effectiveDefinitionVersion,
enforcementMode,
identity,
instanceId,
latestDefinitionVersion,
location,
metadata,
nonComplianceMessages,
notScopes,
overrides,
parameters,
policyDefinitionId,
resourceSelectors,
scope,
selfServeExemptionSettings,
systemData,
type
FROM azure.resource.policy_assignments
WHERE policy_assignment_id = '{{ policy_assignment_id }}' -- required
;
INSERT examples
- create
- create_by_id
- Manifest
This operation creates or updates a policy assignment with the given scope and name. Policy assignments apply to all resources contained within their scope. For example, when you assign a policy at resource group scope, that policy applies to all resources in the group.
INSERT INTO azure.resource.policy_assignments (
properties,
location,
identity,
scope,
policy_assignment_name
)
SELECT
'{{ properties }}',
'{{ location }}',
'{{ identity }}',
'{{ scope }}',
'{{ policy_assignment_name }}'
RETURNING
id,
name,
identity,
location,
properties,
systemData,
type
;
Creates or updates a policy assignment. This operation creates or updates the policy assignment with the given ID. Policy assignments made on a scope apply to all resources contained in that scope. For example, when you assign a policy to a resource group that policy applies to all resources in the group. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid scopes are: management group (format: '/providers/Microsoft.Management/managementGroups/{managementGroup}'), subscription (format: '/subscriptions/{subscriptionId}'), resource group (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}', or resource (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}'.
INSERT INTO azure.resource.policy_assignments (
properties,
location,
identity,
policy_assignment_id
)
SELECT
'{{ properties }}',
'{{ location }}',
'{{ identity }}',
'{{ policy_assignment_id }}'
RETURNING
id,
name,
identity,
location,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: policy_assignments
props:
- name: scope
value: "{{ scope }}"
description: Required parameter for the policy_assignments resource.
- name: policy_assignment_name
value: "{{ policy_assignment_name }}"
description: Required parameter for the policy_assignments resource.
- name: policy_assignment_id
value: "{{ policy_assignment_id }}"
description: Required parameter for the policy_assignments resource.
- name: properties
description: |
Properties for the policy assignment.
value:
displayName: "{{ displayName }}"
policyDefinitionId: "{{ policyDefinitionId }}"
definitionVersion: "{{ definitionVersion }}"
latestDefinitionVersion: "{{ latestDefinitionVersion }}"
effectiveDefinitionVersion: "{{ effectiveDefinitionVersion }}"
scope: "{{ scope }}"
notScopes:
- "{{ notScopes }}"
parameters: "{{ parameters }}"
description: "{{ description }}"
metadata: "{{ metadata }}"
enforcementMode: "{{ enforcementMode }}"
nonComplianceMessages:
- message: "{{ message }}"
policyDefinitionReferenceId: "{{ policyDefinitionReferenceId }}"
resourceSelectors:
- name: "{{ name }}"
selectors: "{{ selectors }}"
overrides:
- kind: "{{ kind }}"
value: "{{ value }}"
selectors: "{{ selectors }}"
assignmentType: "{{ assignmentType }}"
instanceId: "{{ instanceId }}"
selfServeExemptionSettings:
enabled: {{ enabled }}
policyDefinitionReferenceIds:
- "{{ policyDefinitionReferenceIds }}"
- name: location
value: "{{ location }}"
description: |
The location of the policy assignment. Only required when utilizing managed identity.
- name: identity
description: |
The managed identity associated with the policy assignment.
value:
principalId: "{{ principalId }}"
tenantId: "{{ tenantId }}"
type: "{{ type }}"
userAssignedIdentities: "{{ userAssignedIdentities }}"
UPDATE examples
- update
- update_by_id
This operation updates a policy assignment with the given scope and name. Policy assignments apply to all resources contained within their scope. For example, when you assign a policy at resource group scope, that policy applies to all resources in the group.
UPDATE azure.resource.policy_assignments
SET
properties = '{{ properties }}',
location = '{{ location }}',
identity = '{{ identity }}'
WHERE
scope = '{{ scope }}' --required
AND policy_assignment_name = '{{ policy_assignment_name }}' --required
RETURNING
id,
name,
identity,
location,
properties,
systemData,
type;
Updates a policy assignment. This operation updates the policy assignment with the given ID. Policy assignments made on a scope apply to all resources contained in that scope. For example, when you assign a policy to a resource group that policy applies to all resources in the group. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid scopes are: management group (format: '/providers/Microsoft.Management/managementGroups/{managementGroup}'), subscription (format: '/subscriptions/{subscriptionId}'), resource group (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}', or resource (format: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}'.
UPDATE azure.resource.policy_assignments
SET
properties = '{{ properties }}',
location = '{{ location }}',
identity = '{{ identity }}'
WHERE
policy_assignment_id = '{{ policy_assignment_id }}' --required
RETURNING
id,
name,
identity,
location,
properties,
systemData,
type;
DELETE examples
- delete
- delete_by_id
This operation deletes a policy assignment, given its name and the scope it was created in. The scope of a policy assignment is the part of its ID preceding '/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'.
DELETE FROM azure.resource.policy_assignments
WHERE scope = '{{ scope }}' --required
AND policy_assignment_name = '{{ policy_assignment_name }}' --required
;
Deletes a policy assignment. This operation deletes the policy with the given ID. Policy assignment IDs have this format: '{scope}/providers/Microsoft.Authorization/policyAssignments/{policyAssignmentName}'. Valid formats for {scope} are: '/providers/Microsoft.Management/managementGroups/{managementGroup}' (management group), '/subscriptions/{subscriptionId}' (subscription), '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}' (resource group), or '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/[{parentResourcePath}/]{resourceType}/{resourceName}' (resource).
DELETE FROM azure.resource.policy_assignments
WHERE policy_assignment_id = '{{ policy_assignment_id }}' --required
;