policy_definition_versions
Creates, updates, deletes, gets or lists a policy_definition_versions resource.
Overview
| Name | policy_definition_versions |
| Type | Resource |
| Id | azure.resource.policy_definition_versions |
Fields
The following fields are returned by SELECT queries:
- get
- get_at_management_group
- list
- list_by_management_group
- get_built_in
- list_all
- list_built_in
- list_all_at_management_group
- list_all_builtins
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | policy_definition_name, policy_definition_version, subscription_id | This operation retrieves the policy definition version in the given subscription with the given name. | |
get_at_management_group | select | management_group_name, policy_definition_name, policy_definition_version | This operation retrieves the policy definition version in the given management group with the given name. | |
list | select | policy_definition_name, subscription_id | $top | This operation retrieves a list of all the policy definition versions for the given policy definition. |
list_by_management_group | select | management_group_name, policy_definition_name | $top | This operation retrieves a list of all the policy definition versions for the given policy definition in the given management group. |
get_built_in | select | policy_definition_name, policy_definition_version | This operation retrieves the built-in policy definition version with the given name. | |
list_all | select | subscription_id | Lists all policy definition versions within a subscription. This operation lists all the policy definition versions for all policy definitions within a subscription. | |
list_built_in | select | policy_definition_name | $top | This operation retrieves a list of all the built-in policy definition versions for the given policy definition. |
list_all_at_management_group | select | management_group_name | Lists all policy definition versions at management group scope. This operation lists all the policy definition versions for all policy definitions at the management group scope. | |
list_all_builtins | select | Lists all built-in policy definition versions. This operation lists all the built-in policy definition versions for all built-in policy definitions. | ||
create_or_update | insert | policy_definition_name, policy_definition_version, subscription_id | This operation creates or updates a policy definition in the given subscription with the given name. | |
create_or_update_at_management_group | insert | management_group_name, policy_definition_name, policy_definition_version | This operation creates or updates a policy definition version in the given management group with the given name. | |
create_or_update | replace | policy_definition_name, policy_definition_version, subscription_id | This operation creates or updates a policy definition in the given subscription with the given name. | |
create_or_update_at_management_group | replace | management_group_name, policy_definition_name, policy_definition_version | This operation creates or updates a policy definition version in the given management group with the given name. | |
delete | delete | policy_definition_name, policy_definition_version, subscription_id | This operation deletes the policy definition version in the given subscription with the given name. | |
delete_at_management_group | delete | management_group_name, policy_definition_name, policy_definition_version | This operation deletes the policy definition in the given management group with the given name. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
management_group_name | string | The name of the management group. The name is case insensitive. Required. |
policy_definition_name | string | The name of the policy definition. Required. |
policy_definition_version | string | The policy definition version. The format is x.y.z where x is the major version number, y is the minor version number, and z is the patch number. Required. |
subscription_id | string | |
$top | integer | Maximum number of records to return. When the $top filter is not provided, it will return 500 records. Default value is None. |
SELECT examples
- get
- get_at_management_group
- list
- list_by_management_group
- get_built_in
- list_all
- list_built_in
- list_all_at_management_group
- list_all_builtins
This operation retrieves the policy definition version in the given subscription with the given name.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE policy_definition_name = '{{ policy_definition_name }}' -- required
AND policy_definition_version = '{{ policy_definition_version }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
This operation retrieves the policy definition version in the given management group with the given name.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE management_group_name = '{{ management_group_name }}' -- required
AND policy_definition_name = '{{ policy_definition_name }}' -- required
AND policy_definition_version = '{{ policy_definition_version }}' -- required
;
This operation retrieves a list of all the policy definition versions for the given policy definition.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE policy_definition_name = '{{ policy_definition_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $top = '{{ $top }}'
;
This operation retrieves a list of all the policy definition versions for the given policy definition in the given management group.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE management_group_name = '{{ management_group_name }}' -- required
AND policy_definition_name = '{{ policy_definition_name }}' -- required
AND $top = '{{ $top }}'
;
This operation retrieves the built-in policy definition version with the given name.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE policy_definition_name = '{{ policy_definition_name }}' -- required
AND policy_definition_version = '{{ policy_definition_version }}' -- required
;
Lists all policy definition versions within a subscription. This operation lists all the policy definition versions for all policy definitions within a subscription.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE subscription_id = '{{ subscription_id }}' -- required
;
This operation retrieves a list of all the built-in policy definition versions for the given policy definition.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE policy_definition_name = '{{ policy_definition_name }}' -- required
AND $top = '{{ $top }}'
;
Lists all policy definition versions at management group scope. This operation lists all the policy definition versions for all policy definitions at the management group scope.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
WHERE management_group_name = '{{ management_group_name }}' -- required
;
Lists all built-in policy definition versions. This operation lists all the built-in policy definition versions for all built-in policy definitions.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version
FROM azure.resource.policy_definition_versions
;
INSERT examples
- create_or_update
- create_or_update_at_management_group
- Manifest
This operation creates or updates a policy definition in the given subscription with the given name.
INSERT INTO azure.resource.policy_definition_versions (
properties,
policy_definition_name,
policy_definition_version,
subscription_id
)
SELECT
'{{ properties }}',
'{{ policy_definition_name }}',
'{{ policy_definition_version }}',
'{{ subscription_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
This operation creates or updates a policy definition version in the given management group with the given name.
INSERT INTO azure.resource.policy_definition_versions (
properties,
management_group_name,
policy_definition_name,
policy_definition_version
)
SELECT
'{{ properties }}',
'{{ management_group_name }}',
'{{ policy_definition_name }}',
'{{ policy_definition_version }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: policy_definition_versions
props:
- name: policy_definition_name
value: "{{ policy_definition_name }}"
description: Required parameter for the policy_definition_versions resource.
- name: policy_definition_version
value: "{{ policy_definition_version }}"
description: Required parameter for the policy_definition_versions resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the policy_definition_versions resource.
- name: management_group_name
value: "{{ management_group_name }}"
description: Required parameter for the policy_definition_versions resource.
- name: properties
description: |
The policy definition version properties.
value:
policyType: "{{ policyType }}"
mode: "{{ mode }}"
displayName: "{{ displayName }}"
description: "{{ description }}"
policyRule: "{{ policyRule }}"
metadata: "{{ metadata }}"
parameters: "{{ parameters }}"
version: "{{ version }}"
externalEvaluationEnforcementSettings:
missingTokenAction: "{{ missingTokenAction }}"
resultLifespan: "{{ resultLifespan }}"
endpointSettings:
kind: "{{ kind }}"
details: "{{ details }}"
roleDefinitionIds:
- "{{ roleDefinitionIds }}"
REPLACE examples
- create_or_update
- create_or_update_at_management_group
This operation creates or updates a policy definition in the given subscription with the given name.
REPLACE azure.resource.policy_definition_versions
SET
properties = '{{ properties }}'
WHERE
policy_definition_name = '{{ policy_definition_name }}' --required
AND policy_definition_version = '{{ policy_definition_version }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
This operation creates or updates a policy definition version in the given management group with the given name.
REPLACE azure.resource.policy_definition_versions
SET
properties = '{{ properties }}'
WHERE
management_group_name = '{{ management_group_name }}' --required
AND policy_definition_name = '{{ policy_definition_name }}' --required
AND policy_definition_version = '{{ policy_definition_version }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
DELETE examples
- delete
- delete_at_management_group
This operation deletes the policy definition version in the given subscription with the given name.
DELETE FROM azure.resource.policy_definition_versions
WHERE policy_definition_name = '{{ policy_definition_name }}' --required
AND policy_definition_version = '{{ policy_definition_version }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
This operation deletes the policy definition in the given management group with the given name.
DELETE FROM azure.resource.policy_definition_versions
WHERE management_group_name = '{{ management_group_name }}' --required
AND policy_definition_name = '{{ policy_definition_name }}' --required
AND policy_definition_version = '{{ policy_definition_version }}' --required
;