1. Packages
  2. Cisco ISE
  3. API Docs
  4. deviceadmin
  5. AuthorizationRule
Cisco ISE v0.1.4 published on Friday, May 31, 2024 by Pulumi

ise.deviceadmin.AuthorizationRule

Explore with Pulumi AI

ise logo
Cisco ISE v0.1.4 published on Friday, May 31, 2024 by Pulumi

    This resource can manage a Device Admin Authorization Rule.

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as ise from "@pulumi/ise";
    
    const example = new ise.deviceadmin.AuthorizationRule("example", {
        policySetId: "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
        name: "Rule1",
        "default": false,
        rank: 0,
        state: "enabled",
        conditionType: "ConditionAttributes",
        conditionIsNegate: false,
        conditionAttributeName: "Location",
        conditionAttributeValue: "All Locations",
        conditionDictionaryName: "DEVICE",
        conditionOperator: "equals",
        commandSets: ["DenyAllCommands"],
        profile: "Default Shell Profile",
    });
    
    import pulumi
    import pulumi_ise as ise
    
    example = ise.deviceadmin.AuthorizationRule("example",
        policy_set_id="d82952cb-b901-4b09-b363-5ebf39bdbaf9",
        name="Rule1",
        default=False,
        rank=0,
        state="enabled",
        condition_type="ConditionAttributes",
        condition_is_negate=False,
        condition_attribute_name="Location",
        condition_attribute_value="All Locations",
        condition_dictionary_name="DEVICE",
        condition_operator="equals",
        command_sets=["DenyAllCommands"],
        profile="Default Shell Profile")
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-ise/sdk/go/ise/deviceadmin"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := deviceadmin.NewAuthorizationRule(ctx, "example", &deviceadmin.AuthorizationRuleArgs{
    			PolicySetId:             pulumi.String("d82952cb-b901-4b09-b363-5ebf39bdbaf9"),
    			Name:                    pulumi.String("Rule1"),
    			Default:                 pulumi.Bool(false),
    			Rank:                    pulumi.Int(0),
    			State:                   pulumi.String("enabled"),
    			ConditionType:           pulumi.String("ConditionAttributes"),
    			ConditionIsNegate:       pulumi.Bool(false),
    			ConditionAttributeName:  pulumi.String("Location"),
    			ConditionAttributeValue: pulumi.String("All Locations"),
    			ConditionDictionaryName: pulumi.String("DEVICE"),
    			ConditionOperator:       pulumi.String("equals"),
    			CommandSets: pulumi.StringArray{
    				pulumi.String("DenyAllCommands"),
    			},
    			Profile: pulumi.String("Default Shell Profile"),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Ise = Pulumi.Ise;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Ise.DeviceAdmin.AuthorizationRule("example", new()
        {
            PolicySetId = "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
            Name = "Rule1",
            Default = false,
            Rank = 0,
            State = "enabled",
            ConditionType = "ConditionAttributes",
            ConditionIsNegate = false,
            ConditionAttributeName = "Location",
            ConditionAttributeValue = "All Locations",
            ConditionDictionaryName = "DEVICE",
            ConditionOperator = "equals",
            CommandSets = new[]
            {
                "DenyAllCommands",
            },
            Profile = "Default Shell Profile",
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.ise.deviceadmin.AuthorizationRule;
    import com.pulumi.ise.deviceadmin.AuthorizationRuleArgs;
    import java.util.List;
    import java.util.ArrayList;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new AuthorizationRule("example", AuthorizationRuleArgs.builder()
                .policySetId("d82952cb-b901-4b09-b363-5ebf39bdbaf9")
                .name("Rule1")
                .default_(false)
                .rank(0)
                .state("enabled")
                .conditionType("ConditionAttributes")
                .conditionIsNegate(false)
                .conditionAttributeName("Location")
                .conditionAttributeValue("All Locations")
                .conditionDictionaryName("DEVICE")
                .conditionOperator("equals")
                .commandSets("DenyAllCommands")
                .profile("Default Shell Profile")
                .build());
    
        }
    }
    
    resources:
      example:
        type: ise:deviceadmin:AuthorizationRule
        properties:
          policySetId: d82952cb-b901-4b09-b363-5ebf39bdbaf9
          name: Rule1
          default: false
          rank: 0
          state: enabled
          conditionType: ConditionAttributes
          conditionIsNegate: false
          conditionAttributeName: Location
          conditionAttributeValue: All Locations
          conditionDictionaryName: DEVICE
          conditionOperator: equals
          commandSets:
            - DenyAllCommands
          profile: Default Shell Profile
    

    Create AuthorizationRule Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new AuthorizationRule(name: string, args: AuthorizationRuleArgs, opts?: CustomResourceOptions);
    @overload
    def AuthorizationRule(resource_name: str,
                          args: AuthorizationRuleArgs,
                          opts: Optional[ResourceOptions] = None)
    
    @overload
    def AuthorizationRule(resource_name: str,
                          opts: Optional[ResourceOptions] = None,
                          policy_set_id: Optional[str] = None,
                          condition_dictionary_name: Optional[str] = None,
                          condition_type: Optional[str] = None,
                          condition_attribute_value: Optional[str] = None,
                          childrens: Optional[Sequence[AuthorizationRuleChildrenArgs]] = None,
                          condition_dictionary_value: Optional[str] = None,
                          condition_id: Optional[str] = None,
                          condition_attribute_name: Optional[str] = None,
                          condition_operator: Optional[str] = None,
                          condition_is_negate: Optional[bool] = None,
                          default: Optional[bool] = None,
                          name: Optional[str] = None,
                          command_sets: Optional[Sequence[str]] = None,
                          profile: Optional[str] = None,
                          rank: Optional[int] = None,
                          state: Optional[str] = None)
    func NewAuthorizationRule(ctx *Context, name string, args AuthorizationRuleArgs, opts ...ResourceOption) (*AuthorizationRule, error)
    public AuthorizationRule(string name, AuthorizationRuleArgs args, CustomResourceOptions? opts = null)
    public AuthorizationRule(String name, AuthorizationRuleArgs args)
    public AuthorizationRule(String name, AuthorizationRuleArgs args, CustomResourceOptions options)
    
    type: ise:deviceadmin:AuthorizationRule
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    

    Parameters

    name string
    The unique name of the resource.
    args AuthorizationRuleArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args AuthorizationRuleArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args AuthorizationRuleArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args AuthorizationRuleArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args AuthorizationRuleArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var authorizationRuleResource = new Ise.DeviceAdmin.AuthorizationRule("authorizationRuleResource", new()
    {
        PolicySetId = "string",
        ConditionDictionaryName = "string",
        ConditionType = "string",
        ConditionAttributeValue = "string",
        Childrens = new[]
        {
            new Ise.DeviceAdmin.Inputs.AuthorizationRuleChildrenArgs
            {
                ConditionType = "string",
                AttributeName = "string",
                AttributeValue = "string",
                Childrens = new[]
                {
                    new Ise.DeviceAdmin.Inputs.AuthorizationRuleChildrenChildrenArgs
                    {
                        ConditionType = "string",
                        AttributeName = "string",
                        AttributeValue = "string",
                        DictionaryName = "string",
                        DictionaryValue = "string",
                        Id = "string",
                        IsNegate = false,
                        Operator = "string",
                    },
                },
                DictionaryName = "string",
                DictionaryValue = "string",
                Id = "string",
                IsNegate = false,
                Operator = "string",
            },
        },
        ConditionDictionaryValue = "string",
        ConditionId = "string",
        ConditionAttributeName = "string",
        ConditionOperator = "string",
        ConditionIsNegate = false,
        Default = false,
        Name = "string",
        CommandSets = new[]
        {
            "string",
        },
        Profile = "string",
        Rank = 0,
        State = "string",
    });
    
    example, err := deviceadmin.NewAuthorizationRule(ctx, "authorizationRuleResource", &deviceadmin.AuthorizationRuleArgs{
    	PolicySetId:             pulumi.String("string"),
    	ConditionDictionaryName: pulumi.String("string"),
    	ConditionType:           pulumi.String("string"),
    	ConditionAttributeValue: pulumi.String("string"),
    	Childrens: deviceadmin.AuthorizationRuleChildrenArray{
    		&deviceadmin.AuthorizationRuleChildrenArgs{
    			ConditionType:  pulumi.String("string"),
    			AttributeName:  pulumi.String("string"),
    			AttributeValue: pulumi.String("string"),
    			Childrens: deviceadmin.AuthorizationRuleChildrenChildrenArray{
    				&deviceadmin.AuthorizationRuleChildrenChildrenArgs{
    					ConditionType:   pulumi.String("string"),
    					AttributeName:   pulumi.String("string"),
    					AttributeValue:  pulumi.String("string"),
    					DictionaryName:  pulumi.String("string"),
    					DictionaryValue: pulumi.String("string"),
    					Id:              pulumi.String("string"),
    					IsNegate:        pulumi.Bool(false),
    					Operator:        pulumi.String("string"),
    				},
    			},
    			DictionaryName:  pulumi.String("string"),
    			DictionaryValue: pulumi.String("string"),
    			Id:              pulumi.String("string"),
    			IsNegate:        pulumi.Bool(false),
    			Operator:        pulumi.String("string"),
    		},
    	},
    	ConditionDictionaryValue: pulumi.String("string"),
    	ConditionId:              pulumi.String("string"),
    	ConditionAttributeName:   pulumi.String("string"),
    	ConditionOperator:        pulumi.String("string"),
    	ConditionIsNegate:        pulumi.Bool(false),
    	Default:                  pulumi.Bool(false),
    	Name:                     pulumi.String("string"),
    	CommandSets: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	Profile: pulumi.String("string"),
    	Rank:    pulumi.Int(0),
    	State:   pulumi.String("string"),
    })
    
    var authorizationRuleResource = new AuthorizationRule("authorizationRuleResource", AuthorizationRuleArgs.builder()
        .policySetId("string")
        .conditionDictionaryName("string")
        .conditionType("string")
        .conditionAttributeValue("string")
        .childrens(AuthorizationRuleChildrenArgs.builder()
            .conditionType("string")
            .attributeName("string")
            .attributeValue("string")
            .childrens(AuthorizationRuleChildrenChildrenArgs.builder()
                .conditionType("string")
                .attributeName("string")
                .attributeValue("string")
                .dictionaryName("string")
                .dictionaryValue("string")
                .id("string")
                .isNegate(false)
                .operator("string")
                .build())
            .dictionaryName("string")
            .dictionaryValue("string")
            .id("string")
            .isNegate(false)
            .operator("string")
            .build())
        .conditionDictionaryValue("string")
        .conditionId("string")
        .conditionAttributeName("string")
        .conditionOperator("string")
        .conditionIsNegate(false)
        .default_(false)
        .name("string")
        .commandSets("string")
        .profile("string")
        .rank(0)
        .state("string")
        .build());
    
    authorization_rule_resource = ise.deviceadmin.AuthorizationRule("authorizationRuleResource",
        policy_set_id="string",
        condition_dictionary_name="string",
        condition_type="string",
        condition_attribute_value="string",
        childrens=[ise.deviceadmin.AuthorizationRuleChildrenArgs(
            condition_type="string",
            attribute_name="string",
            attribute_value="string",
            childrens=[ise.deviceadmin.AuthorizationRuleChildrenChildrenArgs(
                condition_type="string",
                attribute_name="string",
                attribute_value="string",
                dictionary_name="string",
                dictionary_value="string",
                id="string",
                is_negate=False,
                operator="string",
            )],
            dictionary_name="string",
            dictionary_value="string",
            id="string",
            is_negate=False,
            operator="string",
        )],
        condition_dictionary_value="string",
        condition_id="string",
        condition_attribute_name="string",
        condition_operator="string",
        condition_is_negate=False,
        default=False,
        name="string",
        command_sets=["string"],
        profile="string",
        rank=0,
        state="string")
    
    const authorizationRuleResource = new ise.deviceadmin.AuthorizationRule("authorizationRuleResource", {
        policySetId: "string",
        conditionDictionaryName: "string",
        conditionType: "string",
        conditionAttributeValue: "string",
        childrens: [{
            conditionType: "string",
            attributeName: "string",
            attributeValue: "string",
            childrens: [{
                conditionType: "string",
                attributeName: "string",
                attributeValue: "string",
                dictionaryName: "string",
                dictionaryValue: "string",
                id: "string",
                isNegate: false,
                operator: "string",
            }],
            dictionaryName: "string",
            dictionaryValue: "string",
            id: "string",
            isNegate: false,
            operator: "string",
        }],
        conditionDictionaryValue: "string",
        conditionId: "string",
        conditionAttributeName: "string",
        conditionOperator: "string",
        conditionIsNegate: false,
        "default": false,
        name: "string",
        commandSets: ["string"],
        profile: "string",
        rank: 0,
        state: "string",
    });
    
    type: ise:deviceadmin:AuthorizationRule
    properties:
        childrens:
            - attributeName: string
              attributeValue: string
              childrens:
                - attributeName: string
                  attributeValue: string
                  conditionType: string
                  dictionaryName: string
                  dictionaryValue: string
                  id: string
                  isNegate: false
                  operator: string
              conditionType: string
              dictionaryName: string
              dictionaryValue: string
              id: string
              isNegate: false
              operator: string
        commandSets:
            - string
        conditionAttributeName: string
        conditionAttributeValue: string
        conditionDictionaryName: string
        conditionDictionaryValue: string
        conditionId: string
        conditionIsNegate: false
        conditionOperator: string
        conditionType: string
        default: false
        name: string
        policySetId: string
        profile: string
        rank: 0
        state: string
    

    AuthorizationRule Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    The AuthorizationRule resource accepts the following input properties:

    PolicySetId string
    Policy set ID
    Childrens List<AuthorizationRuleChildren>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    CommandSets List<string>
    Command sets enforce the specified list of commands that can be executed by a device administrator
    ConditionAttributeName string
    Dictionary attribute name
    ConditionAttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    ConditionDictionaryName string
    Dictionary name
    ConditionDictionaryValue string
    Dictionary value
    ConditionId string
    UUID for condition
    ConditionIsNegate bool
    Indicates whereas this condition is in negate mode
    ConditionOperator string
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    ConditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    Default bool
    Indicates if this rule is the default one
    Name string
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    Profile string
    Device admin profiles control the initial login session of the device administrator
    Rank int
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    State string
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    PolicySetId string
    Policy set ID
    Childrens []AuthorizationRuleChildrenArgs
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    CommandSets []string
    Command sets enforce the specified list of commands that can be executed by a device administrator
    ConditionAttributeName string
    Dictionary attribute name
    ConditionAttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    ConditionDictionaryName string
    Dictionary name
    ConditionDictionaryValue string
    Dictionary value
    ConditionId string
    UUID for condition
    ConditionIsNegate bool
    Indicates whereas this condition is in negate mode
    ConditionOperator string
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    ConditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    Default bool
    Indicates if this rule is the default one
    Name string
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    Profile string
    Device admin profiles control the initial login session of the device administrator
    Rank int
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    State string
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    policySetId String
    Policy set ID
    childrens List<AuthorizationRuleChildren>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    commandSets List<String>
    Command sets enforce the specified list of commands that can be executed by a device administrator
    conditionAttributeName String
    Dictionary attribute name
    conditionAttributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    conditionDictionaryName String
    Dictionary name
    conditionDictionaryValue String
    Dictionary value
    conditionId String
    UUID for condition
    conditionIsNegate Boolean
    Indicates whereas this condition is in negate mode
    conditionOperator String
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default_ Boolean
    Indicates if this rule is the default one
    name String
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    profile String
    Device admin profiles control the initial login session of the device administrator
    rank Integer
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state String
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    policySetId string
    Policy set ID
    childrens AuthorizationRuleChildren[]
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    commandSets string[]
    Command sets enforce the specified list of commands that can be executed by a device administrator
    conditionAttributeName string
    Dictionary attribute name
    conditionAttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    conditionDictionaryName string
    Dictionary name
    conditionDictionaryValue string
    Dictionary value
    conditionId string
    UUID for condition
    conditionIsNegate boolean
    Indicates whereas this condition is in negate mode
    conditionOperator string
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default boolean
    Indicates if this rule is the default one
    name string
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    profile string
    Device admin profiles control the initial login session of the device administrator
    rank number
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state string
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    policy_set_id str
    Policy set ID
    childrens Sequence[AuthorizationRuleChildrenArgs]
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    command_sets Sequence[str]
    Command sets enforce the specified list of commands that can be executed by a device administrator
    condition_attribute_name str
    Dictionary attribute name
    condition_attribute_value str
    Attribute value for condition. Value type is specified in dictionary object.
    condition_dictionary_name str
    Dictionary name
    condition_dictionary_value str
    Dictionary value
    condition_id str
    UUID for condition
    condition_is_negate bool
    Indicates whereas this condition is in negate mode
    condition_operator str
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    condition_type str
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default bool
    Indicates if this rule is the default one
    name str
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    profile str
    Device admin profiles control the initial login session of the device administrator
    rank int
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state str
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    policySetId String
    Policy set ID
    childrens List<Property Map>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    commandSets List<String>
    Command sets enforce the specified list of commands that can be executed by a device administrator
    conditionAttributeName String
    Dictionary attribute name
    conditionAttributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    conditionDictionaryName String
    Dictionary name
    conditionDictionaryValue String
    Dictionary value
    conditionId String
    UUID for condition
    conditionIsNegate Boolean
    Indicates whereas this condition is in negate mode
    conditionOperator String
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default Boolean
    Indicates if this rule is the default one
    name String
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    profile String
    Device admin profiles control the initial login session of the device administrator
    rank Number
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state String
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor

    Outputs

    All input properties are implicitly available as output properties. Additionally, the AuthorizationRule resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    Id string
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id str
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.

    Look up Existing AuthorizationRule Resource

    Get an existing AuthorizationRule resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: AuthorizationRuleState, opts?: CustomResourceOptions): AuthorizationRule
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            childrens: Optional[Sequence[AuthorizationRuleChildrenArgs]] = None,
            command_sets: Optional[Sequence[str]] = None,
            condition_attribute_name: Optional[str] = None,
            condition_attribute_value: Optional[str] = None,
            condition_dictionary_name: Optional[str] = None,
            condition_dictionary_value: Optional[str] = None,
            condition_id: Optional[str] = None,
            condition_is_negate: Optional[bool] = None,
            condition_operator: Optional[str] = None,
            condition_type: Optional[str] = None,
            default: Optional[bool] = None,
            name: Optional[str] = None,
            policy_set_id: Optional[str] = None,
            profile: Optional[str] = None,
            rank: Optional[int] = None,
            state: Optional[str] = None) -> AuthorizationRule
    func GetAuthorizationRule(ctx *Context, name string, id IDInput, state *AuthorizationRuleState, opts ...ResourceOption) (*AuthorizationRule, error)
    public static AuthorizationRule Get(string name, Input<string> id, AuthorizationRuleState? state, CustomResourceOptions? opts = null)
    public static AuthorizationRule get(String name, Output<String> id, AuthorizationRuleState state, CustomResourceOptions options)
    Resource lookup is not supported in YAML
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    Childrens List<AuthorizationRuleChildren>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    CommandSets List<string>
    Command sets enforce the specified list of commands that can be executed by a device administrator
    ConditionAttributeName string
    Dictionary attribute name
    ConditionAttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    ConditionDictionaryName string
    Dictionary name
    ConditionDictionaryValue string
    Dictionary value
    ConditionId string
    UUID for condition
    ConditionIsNegate bool
    Indicates whereas this condition is in negate mode
    ConditionOperator string
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    ConditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    Default bool
    Indicates if this rule is the default one
    Name string
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    PolicySetId string
    Policy set ID
    Profile string
    Device admin profiles control the initial login session of the device administrator
    Rank int
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    State string
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    Childrens []AuthorizationRuleChildrenArgs
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    CommandSets []string
    Command sets enforce the specified list of commands that can be executed by a device administrator
    ConditionAttributeName string
    Dictionary attribute name
    ConditionAttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    ConditionDictionaryName string
    Dictionary name
    ConditionDictionaryValue string
    Dictionary value
    ConditionId string
    UUID for condition
    ConditionIsNegate bool
    Indicates whereas this condition is in negate mode
    ConditionOperator string
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    ConditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    Default bool
    Indicates if this rule is the default one
    Name string
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    PolicySetId string
    Policy set ID
    Profile string
    Device admin profiles control the initial login session of the device administrator
    Rank int
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    State string
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    childrens List<AuthorizationRuleChildren>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    commandSets List<String>
    Command sets enforce the specified list of commands that can be executed by a device administrator
    conditionAttributeName String
    Dictionary attribute name
    conditionAttributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    conditionDictionaryName String
    Dictionary name
    conditionDictionaryValue String
    Dictionary value
    conditionId String
    UUID for condition
    conditionIsNegate Boolean
    Indicates whereas this condition is in negate mode
    conditionOperator String
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default_ Boolean
    Indicates if this rule is the default one
    name String
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    policySetId String
    Policy set ID
    profile String
    Device admin profiles control the initial login session of the device administrator
    rank Integer
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state String
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    childrens AuthorizationRuleChildren[]
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    commandSets string[]
    Command sets enforce the specified list of commands that can be executed by a device administrator
    conditionAttributeName string
    Dictionary attribute name
    conditionAttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    conditionDictionaryName string
    Dictionary name
    conditionDictionaryValue string
    Dictionary value
    conditionId string
    UUID for condition
    conditionIsNegate boolean
    Indicates whereas this condition is in negate mode
    conditionOperator string
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default boolean
    Indicates if this rule is the default one
    name string
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    policySetId string
    Policy set ID
    profile string
    Device admin profiles control the initial login session of the device administrator
    rank number
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state string
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    childrens Sequence[AuthorizationRuleChildrenArgs]
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    command_sets Sequence[str]
    Command sets enforce the specified list of commands that can be executed by a device administrator
    condition_attribute_name str
    Dictionary attribute name
    condition_attribute_value str
    Attribute value for condition. Value type is specified in dictionary object.
    condition_dictionary_name str
    Dictionary name
    condition_dictionary_value str
    Dictionary value
    condition_id str
    UUID for condition
    condition_is_negate bool
    Indicates whereas this condition is in negate mode
    condition_operator str
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    condition_type str
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default bool
    Indicates if this rule is the default one
    name str
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    policy_set_id str
    Policy set ID
    profile str
    Device admin profiles control the initial login session of the device administrator
    rank int
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state str
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor
    childrens List<Property Map>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    commandSets List<String>
    Command sets enforce the specified list of commands that can be executed by a device administrator
    conditionAttributeName String
    Dictionary attribute name
    conditionAttributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    conditionDictionaryName String
    Dictionary name
    conditionDictionaryValue String
    Dictionary value
    conditionId String
    UUID for condition
    conditionIsNegate Boolean
    Indicates whereas this condition is in negate mode
    conditionOperator String
    Equality operator - Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute. - Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    default Boolean
    Indicates if this rule is the default one
    name String
    Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
    policySetId String
    Policy set ID
    profile String
    Device admin profiles control the initial login session of the device administrator
    rank Number
    The rank (priority) in relation to other rules. Lower rank is higher priority.
    state String
    The state that the rule is in. A disabled rule cannot be matched. - Choices: disabled, enabled, monitor

    Supporting Types

    AuthorizationRuleChildren, AuthorizationRuleChildrenArgs

    ConditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.

    • Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    AttributeName string
    Dictionary attribute name
    AttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    Childrens List<AuthorizationRuleChildrenChildren>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    DictionaryName string
    Dictionary name
    DictionaryValue string
    Dictionary value
    Id string
    UUID for condition
    IsNegate bool
    Indicates whereas this condition is in negate mode
    Operator string
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    ConditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.

    • Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    AttributeName string
    Dictionary attribute name
    AttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    Childrens []AuthorizationRuleChildrenChildren
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    DictionaryName string
    Dictionary name
    DictionaryValue string
    Dictionary value
    Id string
    UUID for condition
    IsNegate bool
    Indicates whereas this condition is in negate mode
    Operator string
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.

    • Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    attributeName String
    Dictionary attribute name
    attributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    childrens List<AuthorizationRuleChildrenChildren>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    dictionaryName String
    Dictionary name
    dictionaryValue String
    Dictionary value
    id String
    UUID for condition
    isNegate Boolean
    Indicates whereas this condition is in negate mode
    operator String
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType string
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.

    • Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    attributeName string
    Dictionary attribute name
    attributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    childrens AuthorizationRuleChildrenChildren[]
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    dictionaryName string
    Dictionary name
    dictionaryValue string
    Dictionary value
    id string
    UUID for condition
    isNegate boolean
    Indicates whereas this condition is in negate mode
    operator string
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    condition_type str
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.

    • Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    attribute_name str
    Dictionary attribute name
    attribute_value str
    Attribute value for condition. Value type is specified in dictionary object.
    childrens Sequence[AuthorizationRuleChildrenChildren]
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    dictionary_name str
    Dictionary name
    dictionary_value str
    Dictionary value
    id str
    UUID for condition
    is_negate bool
    Indicates whereas this condition is in negate mode
    operator str
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.

    • Choices: ConditionAndBlock, ConditionAttributes, ConditionOrBlock, ConditionReference
    attributeName String
    Dictionary attribute name
    attributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    childrens List<Property Map>
    List of child conditions. condition_type must be one of ConditionAndBlock or ConditionOrBlock.
    dictionaryName String
    Dictionary name
    dictionaryValue String
    Dictionary value
    id String
    UUID for condition
    isNegate Boolean
    Indicates whereas this condition is in negate mode
    operator String
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith

    AuthorizationRuleChildrenChildren, AuthorizationRuleChildrenChildrenArgs

    ConditionType string
    Condition type.

    • Choices: ConditionAttributes, ConditionReference
    AttributeName string
    Dictionary attribute name
    AttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    DictionaryName string
    Dictionary name
    DictionaryValue string
    Dictionary value
    Id string
    UUID for condition
    IsNegate bool
    Indicates whereas this condition is in negate mode
    Operator string
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    ConditionType string
    Condition type.

    • Choices: ConditionAttributes, ConditionReference
    AttributeName string
    Dictionary attribute name
    AttributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    DictionaryName string
    Dictionary name
    DictionaryValue string
    Dictionary value
    Id string
    UUID for condition
    IsNegate bool
    Indicates whereas this condition is in negate mode
    Operator string
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Condition type.

    • Choices: ConditionAttributes, ConditionReference
    attributeName String
    Dictionary attribute name
    attributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    dictionaryName String
    Dictionary name
    dictionaryValue String
    Dictionary value
    id String
    UUID for condition
    isNegate Boolean
    Indicates whereas this condition is in negate mode
    operator String
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType string
    Condition type.

    • Choices: ConditionAttributes, ConditionReference
    attributeName string
    Dictionary attribute name
    attributeValue string
    Attribute value for condition. Value type is specified in dictionary object.
    dictionaryName string
    Dictionary name
    dictionaryValue string
    Dictionary value
    id string
    UUID for condition
    isNegate boolean
    Indicates whereas this condition is in negate mode
    operator string
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    condition_type str
    Condition type.

    • Choices: ConditionAttributes, ConditionReference
    attribute_name str
    Dictionary attribute name
    attribute_value str
    Attribute value for condition. Value type is specified in dictionary object.
    dictionary_name str
    Dictionary name
    dictionary_value str
    Dictionary value
    id str
    UUID for condition
    is_negate bool
    Indicates whereas this condition is in negate mode
    operator str
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith
    conditionType String
    Condition type.

    • Choices: ConditionAttributes, ConditionReference
    attributeName String
    Dictionary attribute name
    attributeValue String
    Attribute value for condition. Value type is specified in dictionary object.
    dictionaryName String
    Dictionary name
    dictionaryValue String
    Dictionary value
    id String
    UUID for condition
    isNegate Boolean
    Indicates whereas this condition is in negate mode
    operator String
    Equality operator

    • Choices: contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith

    Import

    $ pulumi import ise:deviceadmin/authorizationRule:AuthorizationRule example "76d24097-41c4-4558-a4d0-a8c07ac08470,76d24097-41c4-4558-a4d0-a8c07ac08470"
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    ise pulumi/pulumi-ise
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the ise Terraform Provider.
    ise logo
    Cisco ISE v0.1.4 published on Friday, May 31, 2024 by Pulumi