policy_definitions
Creates, updates, deletes, gets or lists a policy_definitions resource.
Overview
| Name | policy_definitions |
| Type | Resource |
| Id | azure.resource.policy_definitions |
Fields
The following fields are returned by SELECT queries:
- get
- get_at_management_group
- list
- list_by_management_group
- get_built_in
- list_built_in
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
versions | array | A list of available versions for this policy definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
versions | array | A list of available versions for this policy definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
versions | array | A list of available versions for this policy definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
versions | array | A list of available versions for this policy definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
versions | array | A list of available versions for this policy definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy definition description. |
displayName | string | The display name of the policy definition. |
externalEvaluationEnforcementSettings | object | The details of the source of external evaluation results required by the policy during enforcement evaluation. |
metadata | object | The policy definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
mode | string | The policy definition mode. Some examples are All, Indexed, Microsoft.KeyVault.Data. |
parameters | object | The parameter definitions for parameters used in the policy rule. The keys are the parameter names. |
policyRule | object | The policy rule. |
policyType | string | The type of policy definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy definition version in #.#.# format. |
versions | array | A list of available versions for this policy definition. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | policy_definition_name, subscription_id | This operation retrieves the policy definition in the given subscription with the given name. | |
get_at_management_group | select | management_group_id, policy_definition_name | This operation retrieves the policy definition in the given management group with the given name. | |
list | select | subscription_id | $filter, $top | This operation retrieves a list of all the policy definitions in a given subscription that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy definitions associated with the subscription, including those that apply directly or from management groups that contain the given subscription. If $filter=atExactScope() is provided, the returned list only includes all policy definitions that at the given subscription. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all policy definitions whose category match the {value}. |
list_by_management_group | select | management_group_id | $filter, $top | This operation retrieves a list of all the policy definitions in a given management group that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy definitions associated with the management group, including those that apply directly or from management groups that contain the given management group. If $filter=atExactScope() is provided, the returned list only includes all policy definitions that at the given management group. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all policy definitions whose category match the {value}. |
get_built_in | select | policy_definition_name | This operation retrieves the built-in policy definition with the given name. | |
list_built_in | select | $filter, $top | This operation retrieves a list of all the built-in policy definitions that match the optional given $filter. If $filter='policyType -eq {value}' is provided, the returned list only includes all built-in policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all built-in policy definitions whose category match the {value}. | |
create_or_update | insert | policy_definition_name, subscription_id | This operation creates or updates a policy definition in the given subscription with the given name. | |
create_or_update_at_management_group | insert | management_group_id, policy_definition_name | This operation creates or updates a policy definition in the given management group with the given name. | |
create_or_update | replace | policy_definition_name, subscription_id | This operation creates or updates a policy definition in the given subscription with the given name. | |
create_or_update_at_management_group | replace | management_group_id, policy_definition_name | This operation creates or updates a policy definition in the given management group with the given name. | |
delete | delete | policy_definition_name, subscription_id | This operation deletes the policy definition in the given subscription with the given name. | |
delete_at_management_group | delete | management_group_id, policy_definition_name | This operation deletes the policy definition in the given management group with the given name. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
management_group_id | string | The ID of the management group. Required. |
policy_definition_name | string | The name of the policy definition to get. Required. |
subscription_id | string | |
$filter | string | The filter to apply on the operation. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, no filtering is performed. If $filter=atExactScope() is provided, the returned list only includes all policy definitions that at the given scope. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all policy definitions whose category match the {value}. Default value is None. |
$top | integer | Maximum number of records to return. When the $top filter is not provided, it will return 500 records. Default value is None. |
SELECT examples
- get
- get_at_management_group
- list
- list_by_management_group
- get_built_in
- list_built_in
This operation retrieves the policy definition in the given subscription with the given name.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_definitions
WHERE policy_definition_name = '{{ policy_definition_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
This operation retrieves the policy definition in the given management group with the given name.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_definitions
WHERE management_group_id = '{{ management_group_id }}' -- required
AND policy_definition_name = '{{ policy_definition_name }}' -- required
;
This operation retrieves a list of all the policy definitions in a given subscription that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy definitions associated with the subscription, including those that apply directly or from management groups that contain the given subscription. If $filter=atExactScope() is provided, the returned list only includes all policy definitions that at the given subscription. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all policy definitions whose category match the {value}.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_definitions
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND $top = '{{ $top }}'
;
This operation retrieves a list of all the policy definitions in a given management group that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy definitions associated with the management group, including those that apply directly or from management groups that contain the given management group. If $filter=atExactScope() is provided, the returned list only includes all policy definitions that at the given management group. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all policy definitions whose category match the {value}.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_definitions
WHERE management_group_id = '{{ management_group_id }}' -- required
AND $filter = '{{ $filter }}'
AND $top = '{{ $top }}'
;
This operation retrieves the built-in policy definition with the given name.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_definitions
WHERE policy_definition_name = '{{ policy_definition_name }}' -- required
;
This operation retrieves a list of all the built-in policy definitions that match the optional given $filter. If $filter='policyType -eq {value}' is provided, the returned list only includes all built-in policy definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all built-in policy definitions whose category match the {value}.
SELECT
id,
name,
description,
displayName,
externalEvaluationEnforcementSettings,
metadata,
mode,
parameters,
policyRule,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_definitions
WHERE $filter = '{{ $filter }}'
AND $top = '{{ $top }}'
;
INSERT examples
- create_or_update
- create_or_update_at_management_group
- Manifest
This operation creates or updates a policy definition in the given subscription with the given name.
INSERT INTO azure.resource.policy_definitions (
properties,
policy_definition_name,
subscription_id
)
SELECT
'{{ properties }}',
'{{ policy_definition_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
This operation creates or updates a policy definition in the given management group with the given name.
INSERT INTO azure.resource.policy_definitions (
properties,
management_group_id,
policy_definition_name
)
SELECT
'{{ properties }}',
'{{ management_group_id }}',
'{{ policy_definition_name }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: policy_definitions
props:
- name: policy_definition_name
value: "{{ policy_definition_name }}"
description: Required parameter for the policy_definitions resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the policy_definitions resource.
- name: management_group_id
value: "{{ management_group_id }}"
description: Required parameter for the policy_definitions resource.
- name: properties
description: |
The policy definition properties.
value:
policyType: "{{ policyType }}"
mode: "{{ mode }}"
displayName: "{{ displayName }}"
description: "{{ description }}"
policyRule: "{{ policyRule }}"
metadata: "{{ metadata }}"
parameters: "{{ parameters }}"
version: "{{ version }}"
versions:
- "{{ versions }}"
externalEvaluationEnforcementSettings:
missingTokenAction: "{{ missingTokenAction }}"
resultLifespan: "{{ resultLifespan }}"
endpointSettings:
kind: "{{ kind }}"
details: "{{ details }}"
roleDefinitionIds:
- "{{ roleDefinitionIds }}"
REPLACE examples
- create_or_update
- create_or_update_at_management_group
This operation creates or updates a policy definition in the given subscription with the given name.
REPLACE azure.resource.policy_definitions
SET
properties = '{{ properties }}'
WHERE
policy_definition_name = '{{ policy_definition_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
This operation creates or updates a policy definition in the given management group with the given name.
REPLACE azure.resource.policy_definitions
SET
properties = '{{ properties }}'
WHERE
management_group_id = '{{ management_group_id }}' --required
AND policy_definition_name = '{{ policy_definition_name }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
DELETE examples
- delete
- delete_at_management_group
This operation deletes the policy definition in the given subscription with the given name.
DELETE FROM azure.resource.policy_definitions
WHERE policy_definition_name = '{{ policy_definition_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
This operation deletes the policy definition in the given management group with the given name.
DELETE FROM azure.resource.policy_definitions
WHERE management_group_id = '{{ management_group_id }}' --required
AND policy_definition_name = '{{ policy_definition_name }}' --required
;