policy_set_definitions
Creates, updates, deletes, gets or lists a policy_set_definitions resource.
Overview
| Name | policy_set_definitions |
| Type | Resource |
| Id | azure.resource.policy_set_definitions |
Fields
The following fields are returned by SELECT queries:
- get
- get_at_management_group
- list
- list_by_management_group
- get_built_in
- list_built_in
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy set definition description. |
displayName | string | The display name of the policy set definition. |
metadata | object | The policy set definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
parameters | object | The policy set definition parameters that can be used in policy definition references. |
policyDefinitionGroups | array | The metadata describing groups of policy definition references within the policy set definition. |
policyDefinitions | array | An array of policy definition references. Required. |
policyType | string | The type of policy set definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy set definition version in #.#.# format. |
versions | array | A list of available versions for this policy set definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy set definition description. |
displayName | string | The display name of the policy set definition. |
metadata | object | The policy set definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
parameters | object | The policy set definition parameters that can be used in policy definition references. |
policyDefinitionGroups | array | The metadata describing groups of policy definition references within the policy set definition. |
policyDefinitions | array | An array of policy definition references. Required. |
policyType | string | The type of policy set definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy set definition version in #.#.# format. |
versions | array | A list of available versions for this policy set definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy set definition description. |
displayName | string | The display name of the policy set definition. |
metadata | object | The policy set definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
parameters | object | The policy set definition parameters that can be used in policy definition references. |
policyDefinitionGroups | array | The metadata describing groups of policy definition references within the policy set definition. |
policyDefinitions | array | An array of policy definition references. Required. |
policyType | string | The type of policy set definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy set definition version in #.#.# format. |
versions | array | A list of available versions for this policy set definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy set definition description. |
displayName | string | The display name of the policy set definition. |
metadata | object | The policy set definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
parameters | object | The policy set definition parameters that can be used in policy definition references. |
policyDefinitionGroups | array | The metadata describing groups of policy definition references within the policy set definition. |
policyDefinitions | array | An array of policy definition references. Required. |
policyType | string | The type of policy set definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy set definition version in #.#.# format. |
versions | array | A list of available versions for this policy set definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy set definition description. |
displayName | string | The display name of the policy set definition. |
metadata | object | The policy set definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
parameters | object | The policy set definition parameters that can be used in policy definition references. |
policyDefinitionGroups | array | The metadata describing groups of policy definition references within the policy set definition. |
policyDefinitions | array | An array of policy definition references. Required. |
policyType | string | The type of policy set definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy set definition version in #.#.# format. |
versions | array | A list of available versions for this policy set definition. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
description | string | The policy set definition description. |
displayName | string | The display name of the policy set definition. |
metadata | object | The policy set definition metadata. Metadata is an open ended object and is typically a collection of key value pairs. |
parameters | object | The policy set definition parameters that can be used in policy definition references. |
policyDefinitionGroups | array | The metadata describing groups of policy definition references within the policy set definition. |
policyDefinitions | array | An array of policy definition references. Required. |
policyType | string | The type of policy set definition. Possible values are NotSpecified, BuiltIn, Custom, and Static. Known values are: "NotSpecified", "BuiltIn", "Custom", and "Static". (NotSpecified, BuiltIn, Custom, Static) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
version | string | The policy set definition version in #.#.# format. |
versions | array | A list of available versions for this policy set definition. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | policy_set_definition_name, subscription_id | $expand | This operation retrieves the policy set definition in the given subscription with the given name. |
get_at_management_group | select | management_group_id, policy_set_definition_name | $expand | This operation retrieves the policy set definition in the given management group with the given name. |
list | select | subscription_id | $filter, $expand, $top | This operation retrieves a list of all the policy set definitions in a given subscription that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy set definitions associated with the subscription, including those that apply directly or from management groups that contain the given subscription. If $filter=atExactScope() is provided, the returned list only includes all policy set definitions that at the given subscription. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy set definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn and Custom. If $filter='category -eq {value}' is provided, the returned list only includes all policy set definitions whose category match the {value}. |
list_by_management_group | select | management_group_id | $filter, $expand, $top | This operation retrieves a list of all the policy set definitions in a given management group that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy set definitions associated with the management group, including those that apply directly or from management groups that contain the given management group. If $filter=atExactScope() is provided, the returned list only includes all policy set definitions that at the given management group. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy set definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn and Custom. If $filter='category -eq {value}' is provided, the returned list only includes all policy set definitions whose category match the {value}. |
get_built_in | select | policy_set_definition_name | $expand | This operation retrieves the built-in policy set definition with the given name. |
list_built_in | select | $filter, $expand, $top | This operation retrieves a list of all the built-in policy set definitions that match the optional given $filter. If $filter='category -eq {value}' is provided, the returned list only includes all built-in policy set definitions whose category match the {value}. | |
create_or_update | insert | policy_set_definition_name, subscription_id | This operation creates or updates a policy set definition in the given subscription with the given name. | |
create_or_update_at_management_group | insert | management_group_id, policy_set_definition_name | This operation creates or updates a policy set definition in the given management group with the given name. | |
create_or_update | replace | policy_set_definition_name, subscription_id | This operation creates or updates a policy set definition in the given subscription with the given name. | |
create_or_update_at_management_group | replace | management_group_id, policy_set_definition_name | This operation creates or updates a policy set definition in the given management group with the given name. | |
delete | delete | policy_set_definition_name, subscription_id | This operation deletes the policy set definition in the given subscription with the given name. | |
delete_at_management_group | delete | management_group_id, policy_set_definition_name | This operation deletes the policy set definition in the given management group with the given name. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
management_group_id | string | The ID of the management group. Required. |
policy_set_definition_name | string | The name of the policy set definition to get. Required. |
subscription_id | string | |
$expand | string | Comma-separated list of additional properties to be included in the response. Supported values are 'LatestDefinitionVersion, EffectiveDefinitionVersion'. Default value is None. |
$filter | string | The filter to apply on the operation. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, no filtering is performed. If $filter=atExactScope() is provided, the returned list only includes all policy set definitions that at the given scope. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy set definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn, Custom, and Static. If $filter='category -eq {value}' is provided, the returned list only includes all policy set definitions whose category match the {value}. Default value is None. |
$top | integer | Maximum number of records to return. When the $top filter is not provided, it will return 500 records. Default value is None. |
SELECT examples
- get
- get_at_management_group
- list
- list_by_management_group
- get_built_in
- list_built_in
This operation retrieves the policy set definition in the given subscription with the given name.
SELECT
id,
name,
description,
displayName,
metadata,
parameters,
policyDefinitionGroups,
policyDefinitions,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_set_definitions
WHERE policy_set_definition_name = '{{ policy_set_definition_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $expand = '{{ $expand }}'
;
This operation retrieves the policy set definition in the given management group with the given name.
SELECT
id,
name,
description,
displayName,
metadata,
parameters,
policyDefinitionGroups,
policyDefinitions,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_set_definitions
WHERE management_group_id = '{{ management_group_id }}' -- required
AND policy_set_definition_name = '{{ policy_set_definition_name }}' -- required
AND $expand = '{{ $expand }}'
;
This operation retrieves a list of all the policy set definitions in a given subscription that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy set definitions associated with the subscription, including those that apply directly or from management groups that contain the given subscription. If $filter=atExactScope() is provided, the returned list only includes all policy set definitions that at the given subscription. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy set definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn and Custom. If $filter='category -eq {value}' is provided, the returned list only includes all policy set definitions whose category match the {value}.
SELECT
id,
name,
description,
displayName,
metadata,
parameters,
policyDefinitionGroups,
policyDefinitions,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_set_definitions
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
This operation retrieves a list of all the policy set definitions in a given management group that match the optional given $filter. Valid values for $filter are: 'atExactScope()', 'policyType -eq {value}' or 'category eq '{value}''. If $filter is not provided, the unfiltered list includes all policy set definitions associated with the management group, including those that apply directly or from management groups that contain the given management group. If $filter=atExactScope() is provided, the returned list only includes all policy set definitions that at the given management group. If $filter='policyType -eq {value}' is provided, the returned list only includes all policy set definitions whose type match the {value}. Possible policyType values are NotSpecified, BuiltIn and Custom. If $filter='category -eq {value}' is provided, the returned list only includes all policy set definitions whose category match the {value}.
SELECT
id,
name,
description,
displayName,
metadata,
parameters,
policyDefinitionGroups,
policyDefinitions,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_set_definitions
WHERE management_group_id = '{{ management_group_id }}' -- required
AND $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
This operation retrieves the built-in policy set definition with the given name.
SELECT
id,
name,
description,
displayName,
metadata,
parameters,
policyDefinitionGroups,
policyDefinitions,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_set_definitions
WHERE policy_set_definition_name = '{{ policy_set_definition_name }}' -- required
AND $expand = '{{ $expand }}'
;
This operation retrieves a list of all the built-in policy set definitions that match the optional given $filter. If $filter='category -eq {value}' is provided, the returned list only includes all built-in policy set definitions whose category match the {value}.
SELECT
id,
name,
description,
displayName,
metadata,
parameters,
policyDefinitionGroups,
policyDefinitions,
policyType,
systemData,
type,
version,
versions
FROM azure.resource.policy_set_definitions
WHERE $filter = '{{ $filter }}'
AND $expand = '{{ $expand }}'
AND $top = '{{ $top }}'
;
INSERT examples
- create_or_update
- create_or_update_at_management_group
- Manifest
This operation creates or updates a policy set definition in the given subscription with the given name.
INSERT INTO azure.resource.policy_set_definitions (
properties,
policy_set_definition_name,
subscription_id
)
SELECT
'{{ properties }}',
'{{ policy_set_definition_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
This operation creates or updates a policy set definition in the given management group with the given name.
INSERT INTO azure.resource.policy_set_definitions (
properties,
management_group_id,
policy_set_definition_name
)
SELECT
'{{ properties }}',
'{{ management_group_id }}',
'{{ policy_set_definition_name }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: policy_set_definitions
props:
- name: policy_set_definition_name
value: "{{ policy_set_definition_name }}"
description: Required parameter for the policy_set_definitions resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the policy_set_definitions resource.
- name: management_group_id
value: "{{ management_group_id }}"
description: Required parameter for the policy_set_definitions resource.
- name: properties
description: |
The policy set definition properties.
value:
policyType: "{{ policyType }}"
displayName: "{{ displayName }}"
description: "{{ description }}"
metadata: "{{ metadata }}"
parameters: "{{ parameters }}"
policyDefinitions:
- policyDefinitionId: "{{ policyDefinitionId }}"
definitionVersion: "{{ definitionVersion }}"
latestDefinitionVersion: "{{ latestDefinitionVersion }}"
effectiveDefinitionVersion: "{{ effectiveDefinitionVersion }}"
parameters: "{{ parameters }}"
policyDefinitionReferenceId: "{{ policyDefinitionReferenceId }}"
groupNames: "{{ groupNames }}"
policyDefinitionGroups:
- name: "{{ name }}"
displayName: "{{ displayName }}"
category: "{{ category }}"
description: "{{ description }}"
additionalMetadataId: "{{ additionalMetadataId }}"
version: "{{ version }}"
versions:
- "{{ versions }}"
REPLACE examples
- create_or_update
- create_or_update_at_management_group
This operation creates or updates a policy set definition in the given subscription with the given name.
REPLACE azure.resource.policy_set_definitions
SET
properties = '{{ properties }}'
WHERE
policy_set_definition_name = '{{ policy_set_definition_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
This operation creates or updates a policy set definition in the given management group with the given name.
REPLACE azure.resource.policy_set_definitions
SET
properties = '{{ properties }}'
WHERE
management_group_id = '{{ management_group_id }}' --required
AND policy_set_definition_name = '{{ policy_set_definition_name }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
DELETE examples
- delete
- delete_at_management_group
This operation deletes the policy set definition in the given subscription with the given name.
DELETE FROM azure.resource.policy_set_definitions
WHERE policy_set_definition_name = '{{ policy_set_definition_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
This operation deletes the policy set definition in the given management group with the given name.
DELETE FROM azure.resource.policy_set_definitions
WHERE management_group_id = '{{ management_group_id }}' --required
AND policy_set_definition_name = '{{ policy_set_definition_name }}' --required
;