azure-native.authorization.AccessReviewScheduleDefinitionById
Explore with Pulumi AI
Access Review Schedule Definition. Azure REST API version: 2021-12-01-preview. Prior API version in Azure Native 1.x: 2021-03-01-preview.
Import
An existing resource can be imported using its type token, name, and identifier, e.g.
$ pulumi import azure-native:authorization:AccessReviewScheduleDefinitionById myresource1 /subscriptions/{subscriptionId}/providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}
Create AccessReviewScheduleDefinitionById Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new AccessReviewScheduleDefinitionById(name: string, args?: AccessReviewScheduleDefinitionByIdArgs, opts?: CustomResourceOptions);
@overload
def AccessReviewScheduleDefinitionById(resource_name: str,
args: Optional[AccessReviewScheduleDefinitionByIdArgs] = None,
opts: Optional[ResourceOptions] = None)
@overload
def AccessReviewScheduleDefinitionById(resource_name: str,
opts: Optional[ResourceOptions] = None,
auto_apply_decisions_enabled: Optional[bool] = None,
backup_reviewers: Optional[Sequence[AccessReviewReviewerArgs]] = None,
default_decision: Optional[Union[str, DefaultDecisionType]] = None,
default_decision_enabled: Optional[bool] = None,
description_for_admins: Optional[str] = None,
description_for_reviewers: Optional[str] = None,
display_name: Optional[str] = None,
end_date: Optional[str] = None,
exclude_resource_id: Optional[str] = None,
exclude_role_definition_id: Optional[str] = None,
expand_nested_memberships: Optional[bool] = None,
inactive_duration: Optional[str] = None,
include_access_below_resource: Optional[bool] = None,
include_inherited_access: Optional[bool] = None,
instance_duration_in_days: Optional[int] = None,
instances: Optional[Sequence[AccessReviewInstanceArgs]] = None,
interval: Optional[int] = None,
justification_required_on_approval: Optional[bool] = None,
mail_notifications_enabled: Optional[bool] = None,
number_of_occurrences: Optional[int] = None,
recommendation_look_back_duration: Optional[str] = None,
recommendations_enabled: Optional[bool] = None,
reminder_notifications_enabled: Optional[bool] = None,
reviewers: Optional[Sequence[AccessReviewReviewerArgs]] = None,
schedule_definition_id: Optional[str] = None,
start_date: Optional[str] = None,
type: Optional[Union[str, AccessReviewRecurrenceRangeType]] = None)
func NewAccessReviewScheduleDefinitionById(ctx *Context, name string, args *AccessReviewScheduleDefinitionByIdArgs, opts ...ResourceOption) (*AccessReviewScheduleDefinitionById, error)
public AccessReviewScheduleDefinitionById(string name, AccessReviewScheduleDefinitionByIdArgs? args = null, CustomResourceOptions? opts = null)
public AccessReviewScheduleDefinitionById(String name, AccessReviewScheduleDefinitionByIdArgs args)
public AccessReviewScheduleDefinitionById(String name, AccessReviewScheduleDefinitionByIdArgs args, CustomResourceOptions options)
type: azure-native:authorization:AccessReviewScheduleDefinitionById
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
Parameters
- name string
- The unique name of the resource.
- args AccessReviewScheduleDefinitionByIdArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args AccessReviewScheduleDefinitionByIdArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args AccessReviewScheduleDefinitionByIdArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args AccessReviewScheduleDefinitionByIdArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args AccessReviewScheduleDefinitionByIdArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var accessReviewScheduleDefinitionByIdResource = new AzureNative.Authorization.AccessReviewScheduleDefinitionById("accessReviewScheduleDefinitionByIdResource", new()
{
AutoApplyDecisionsEnabled = false,
BackupReviewers = new[]
{
new AzureNative.Authorization.Inputs.AccessReviewReviewerArgs
{
PrincipalId = "string",
},
},
DefaultDecision = "string",
DefaultDecisionEnabled = false,
DescriptionForAdmins = "string",
DescriptionForReviewers = "string",
DisplayName = "string",
EndDate = "string",
ExcludeResourceId = "string",
ExcludeRoleDefinitionId = "string",
ExpandNestedMemberships = false,
InactiveDuration = "string",
IncludeAccessBelowResource = false,
IncludeInheritedAccess = false,
InstanceDurationInDays = 0,
Instances = new[]
{
new AzureNative.Authorization.Inputs.AccessReviewInstanceArgs
{
BackupReviewers = new[]
{
new AzureNative.Authorization.Inputs.AccessReviewReviewerArgs
{
PrincipalId = "string",
},
},
EndDateTime = "string",
Reviewers = new[]
{
new AzureNative.Authorization.Inputs.AccessReviewReviewerArgs
{
PrincipalId = "string",
},
},
StartDateTime = "string",
},
},
Interval = 0,
JustificationRequiredOnApproval = false,
MailNotificationsEnabled = false,
NumberOfOccurrences = 0,
RecommendationLookBackDuration = "string",
RecommendationsEnabled = false,
ReminderNotificationsEnabled = false,
Reviewers = new[]
{
new AzureNative.Authorization.Inputs.AccessReviewReviewerArgs
{
PrincipalId = "string",
},
},
ScheduleDefinitionId = "string",
StartDate = "string",
Type = "string",
});
example, err := authorization.NewAccessReviewScheduleDefinitionById(ctx, "accessReviewScheduleDefinitionByIdResource", &authorization.AccessReviewScheduleDefinitionByIdArgs{
AutoApplyDecisionsEnabled: pulumi.Bool(false),
BackupReviewers: authorization.AccessReviewReviewerArray{
&authorization.AccessReviewReviewerArgs{
PrincipalId: pulumi.String("string"),
},
},
DefaultDecision: pulumi.String("string"),
DefaultDecisionEnabled: pulumi.Bool(false),
DescriptionForAdmins: pulumi.String("string"),
DescriptionForReviewers: pulumi.String("string"),
DisplayName: pulumi.String("string"),
EndDate: pulumi.String("string"),
ExcludeResourceId: pulumi.String("string"),
ExcludeRoleDefinitionId: pulumi.String("string"),
ExpandNestedMemberships: pulumi.Bool(false),
InactiveDuration: pulumi.String("string"),
IncludeAccessBelowResource: pulumi.Bool(false),
IncludeInheritedAccess: pulumi.Bool(false),
InstanceDurationInDays: pulumi.Int(0),
Instances: authorization.AccessReviewInstanceArray{
&authorization.AccessReviewInstanceArgs{
BackupReviewers: authorization.AccessReviewReviewerArray{
&authorization.AccessReviewReviewerArgs{
PrincipalId: pulumi.String("string"),
},
},
EndDateTime: pulumi.String("string"),
Reviewers: authorization.AccessReviewReviewerArray{
&authorization.AccessReviewReviewerArgs{
PrincipalId: pulumi.String("string"),
},
},
StartDateTime: pulumi.String("string"),
},
},
Interval: pulumi.Int(0),
JustificationRequiredOnApproval: pulumi.Bool(false),
MailNotificationsEnabled: pulumi.Bool(false),
NumberOfOccurrences: pulumi.Int(0),
RecommendationLookBackDuration: pulumi.String("string"),
RecommendationsEnabled: pulumi.Bool(false),
ReminderNotificationsEnabled: pulumi.Bool(false),
Reviewers: authorization.AccessReviewReviewerArray{
&authorization.AccessReviewReviewerArgs{
PrincipalId: pulumi.String("string"),
},
},
ScheduleDefinitionId: pulumi.String("string"),
StartDate: pulumi.String("string"),
Type: pulumi.String("string"),
})
var accessReviewScheduleDefinitionByIdResource = new AccessReviewScheduleDefinitionById("accessReviewScheduleDefinitionByIdResource", AccessReviewScheduleDefinitionByIdArgs.builder()
.autoApplyDecisionsEnabled(false)
.backupReviewers(AccessReviewReviewerArgs.builder()
.principalId("string")
.build())
.defaultDecision("string")
.defaultDecisionEnabled(false)
.descriptionForAdmins("string")
.descriptionForReviewers("string")
.displayName("string")
.endDate("string")
.excludeResourceId("string")
.excludeRoleDefinitionId("string")
.expandNestedMemberships(false)
.inactiveDuration("string")
.includeAccessBelowResource(false)
.includeInheritedAccess(false)
.instanceDurationInDays(0)
.instances(AccessReviewInstanceArgs.builder()
.backupReviewers(AccessReviewReviewerArgs.builder()
.principalId("string")
.build())
.endDateTime("string")
.reviewers(AccessReviewReviewerArgs.builder()
.principalId("string")
.build())
.startDateTime("string")
.build())
.interval(0)
.justificationRequiredOnApproval(false)
.mailNotificationsEnabled(false)
.numberOfOccurrences(0)
.recommendationLookBackDuration("string")
.recommendationsEnabled(false)
.reminderNotificationsEnabled(false)
.reviewers(AccessReviewReviewerArgs.builder()
.principalId("string")
.build())
.scheduleDefinitionId("string")
.startDate("string")
.type("string")
.build());
access_review_schedule_definition_by_id_resource = azure_native.authorization.AccessReviewScheduleDefinitionById("accessReviewScheduleDefinitionByIdResource",
auto_apply_decisions_enabled=False,
backup_reviewers=[azure_native.authorization.AccessReviewReviewerArgs(
principal_id="string",
)],
default_decision="string",
default_decision_enabled=False,
description_for_admins="string",
description_for_reviewers="string",
display_name="string",
end_date="string",
exclude_resource_id="string",
exclude_role_definition_id="string",
expand_nested_memberships=False,
inactive_duration="string",
include_access_below_resource=False,
include_inherited_access=False,
instance_duration_in_days=0,
instances=[azure_native.authorization.AccessReviewInstanceArgs(
backup_reviewers=[azure_native.authorization.AccessReviewReviewerArgs(
principal_id="string",
)],
end_date_time="string",
reviewers=[azure_native.authorization.AccessReviewReviewerArgs(
principal_id="string",
)],
start_date_time="string",
)],
interval=0,
justification_required_on_approval=False,
mail_notifications_enabled=False,
number_of_occurrences=0,
recommendation_look_back_duration="string",
recommendations_enabled=False,
reminder_notifications_enabled=False,
reviewers=[azure_native.authorization.AccessReviewReviewerArgs(
principal_id="string",
)],
schedule_definition_id="string",
start_date="string",
type="string")
const accessReviewScheduleDefinitionByIdResource = new azure_native.authorization.AccessReviewScheduleDefinitionById("accessReviewScheduleDefinitionByIdResource", {
autoApplyDecisionsEnabled: false,
backupReviewers: [{
principalId: "string",
}],
defaultDecision: "string",
defaultDecisionEnabled: false,
descriptionForAdmins: "string",
descriptionForReviewers: "string",
displayName: "string",
endDate: "string",
excludeResourceId: "string",
excludeRoleDefinitionId: "string",
expandNestedMemberships: false,
inactiveDuration: "string",
includeAccessBelowResource: false,
includeInheritedAccess: false,
instanceDurationInDays: 0,
instances: [{
backupReviewers: [{
principalId: "string",
}],
endDateTime: "string",
reviewers: [{
principalId: "string",
}],
startDateTime: "string",
}],
interval: 0,
justificationRequiredOnApproval: false,
mailNotificationsEnabled: false,
numberOfOccurrences: 0,
recommendationLookBackDuration: "string",
recommendationsEnabled: false,
reminderNotificationsEnabled: false,
reviewers: [{
principalId: "string",
}],
scheduleDefinitionId: "string",
startDate: "string",
type: "string",
});
type: azure-native:authorization:AccessReviewScheduleDefinitionById
properties:
autoApplyDecisionsEnabled: false
backupReviewers:
- principalId: string
defaultDecision: string
defaultDecisionEnabled: false
descriptionForAdmins: string
descriptionForReviewers: string
displayName: string
endDate: string
excludeResourceId: string
excludeRoleDefinitionId: string
expandNestedMemberships: false
inactiveDuration: string
includeAccessBelowResource: false
includeInheritedAccess: false
instanceDurationInDays: 0
instances:
- backupReviewers:
- principalId: string
endDateTime: string
reviewers:
- principalId: string
startDateTime: string
interval: 0
justificationRequiredOnApproval: false
mailNotificationsEnabled: false
numberOfOccurrences: 0
recommendationLookBackDuration: string
recommendationsEnabled: false
reminderNotificationsEnabled: false
reviewers:
- principalId: string
scheduleDefinitionId: string
startDate: string
type: string
AccessReviewScheduleDefinitionById Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
The AccessReviewScheduleDefinitionById resource accepts the following input properties:
- Auto
Apply boolDecisions Enabled - Flag to indicate whether auto-apply capability, to automatically change the target object access resource, is enabled. If not enabled, a user must, after the review completes, apply the access review.
- Backup
Reviewers List<Pulumi.Azure Native. Authorization. Inputs. Access Review Reviewer> - This is the collection of backup reviewers.
- Default
Decision string | Pulumi.Azure Native. Authorization. Default Decision Type - This specifies the behavior for the autoReview feature when an access review completes.
- Default
Decision boolEnabled - Flag to indicate whether reviewers are required to provide a justification when reviewing access.
- Description
For stringAdmins - The description provided by the access review creator and visible to admins.
- Description
For stringReviewers - The description provided by the access review creator to be shown to reviewers.
- Display
Name string - The display name for the schedule definition.
- End
Date string - The DateTime when the review is scheduled to end. Required if type is endDate
- Exclude
Resource stringId - This is used to indicate the resource id(s) to exclude
- Exclude
Role stringDefinition Id - This is used to indicate the role definition id(s) to exclude
- Expand
Nested boolMemberships - Flag to indicate whether to expand nested memberships or not.
- Inactive
Duration string - Duration users are inactive for. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- Include
Access boolBelow Resource - Flag to indicate whether to expand nested memberships or not.
- Include
Inherited boolAccess - Flag to indicate whether to expand nested memberships or not.
- Instance
Duration intIn Days - The duration in days for an instance.
- Instances
List<Pulumi.
Azure Native. Authorization. Inputs. Access Review Instance> - This is the collection of instances returned when one does an expand on it.
- Interval int
- The interval for recurrence. For a quarterly review, the interval is 3 for type : absoluteMonthly.
- Justification
Required boolOn Approval - Flag to indicate whether the reviewer is required to pass justification when recording a decision.
- Mail
Notifications boolEnabled - Flag to indicate whether sending mails to reviewers and the review creator is enabled.
- Number
Of intOccurrences - The number of times to repeat the access review. Required and must be positive if type is numbered.
- Recommendation
Look stringBack Duration - Recommendations for access reviews are calculated by looking back at 30 days of data(w.r.t the start date of the review) by default. However, in some scenarios, customers want to change how far back to look at and want to configure 60 days, 90 days, etc. instead. This setting allows customers to configure this duration. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- Recommendations
Enabled bool - Flag to indicate whether showing recommendations to reviewers is enabled.
- Reminder
Notifications boolEnabled - Flag to indicate whether sending reminder emails to reviewers are enabled.
- Reviewers
List<Pulumi.
Azure Native. Authorization. Inputs. Access Review Reviewer> - This is the collection of reviewers.
- Schedule
Definition stringId - The id of the access review schedule definition.
- Start
Date string - The DateTime when the review is scheduled to be start. This could be a date in the future. Required on create.
- Type
string | Pulumi.
Azure Native. Authorization. Access Review Recurrence Range Type - The recurrence range type. The possible values are: endDate, noEnd, numbered.
- Auto
Apply boolDecisions Enabled - Flag to indicate whether auto-apply capability, to automatically change the target object access resource, is enabled. If not enabled, a user must, after the review completes, apply the access review.
- Backup
Reviewers []AccessReview Reviewer Args - This is the collection of backup reviewers.
- Default
Decision string | DefaultDecision Type - This specifies the behavior for the autoReview feature when an access review completes.
- Default
Decision boolEnabled - Flag to indicate whether reviewers are required to provide a justification when reviewing access.
- Description
For stringAdmins - The description provided by the access review creator and visible to admins.
- Description
For stringReviewers - The description provided by the access review creator to be shown to reviewers.
- Display
Name string - The display name for the schedule definition.
- End
Date string - The DateTime when the review is scheduled to end. Required if type is endDate
- Exclude
Resource stringId - This is used to indicate the resource id(s) to exclude
- Exclude
Role stringDefinition Id - This is used to indicate the role definition id(s) to exclude
- Expand
Nested boolMemberships - Flag to indicate whether to expand nested memberships or not.
- Inactive
Duration string - Duration users are inactive for. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- Include
Access boolBelow Resource - Flag to indicate whether to expand nested memberships or not.
- Include
Inherited boolAccess - Flag to indicate whether to expand nested memberships or not.
- Instance
Duration intIn Days - The duration in days for an instance.
- Instances
[]Access
Review Instance Args - This is the collection of instances returned when one does an expand on it.
- Interval int
- The interval for recurrence. For a quarterly review, the interval is 3 for type : absoluteMonthly.
- Justification
Required boolOn Approval - Flag to indicate whether the reviewer is required to pass justification when recording a decision.
- Mail
Notifications boolEnabled - Flag to indicate whether sending mails to reviewers and the review creator is enabled.
- Number
Of intOccurrences - The number of times to repeat the access review. Required and must be positive if type is numbered.
- Recommendation
Look stringBack Duration - Recommendations for access reviews are calculated by looking back at 30 days of data(w.r.t the start date of the review) by default. However, in some scenarios, customers want to change how far back to look at and want to configure 60 days, 90 days, etc. instead. This setting allows customers to configure this duration. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- Recommendations
Enabled bool - Flag to indicate whether showing recommendations to reviewers is enabled.
- Reminder
Notifications boolEnabled - Flag to indicate whether sending reminder emails to reviewers are enabled.
- Reviewers
[]Access
Review Reviewer Args - This is the collection of reviewers.
- Schedule
Definition stringId - The id of the access review schedule definition.
- Start
Date string - The DateTime when the review is scheduled to be start. This could be a date in the future. Required on create.
- Type
string | Access
Review Recurrence Range Type - The recurrence range type. The possible values are: endDate, noEnd, numbered.
- auto
Apply BooleanDecisions Enabled - Flag to indicate whether auto-apply capability, to automatically change the target object access resource, is enabled. If not enabled, a user must, after the review completes, apply the access review.
- backup
Reviewers List<AccessReview Reviewer> - This is the collection of backup reviewers.
- default
Decision String | DefaultDecision Type - This specifies the behavior for the autoReview feature when an access review completes.
- default
Decision BooleanEnabled - Flag to indicate whether reviewers are required to provide a justification when reviewing access.
- description
For StringAdmins - The description provided by the access review creator and visible to admins.
- description
For StringReviewers - The description provided by the access review creator to be shown to reviewers.
- display
Name String - The display name for the schedule definition.
- end
Date String - The DateTime when the review is scheduled to end. Required if type is endDate
- exclude
Resource StringId - This is used to indicate the resource id(s) to exclude
- exclude
Role StringDefinition Id - This is used to indicate the role definition id(s) to exclude
- expand
Nested BooleanMemberships - Flag to indicate whether to expand nested memberships or not.
- inactive
Duration String - Duration users are inactive for. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- include
Access BooleanBelow Resource - Flag to indicate whether to expand nested memberships or not.
- include
Inherited BooleanAccess - Flag to indicate whether to expand nested memberships or not.
- instance
Duration IntegerIn Days - The duration in days for an instance.
- instances
List<Access
Review Instance> - This is the collection of instances returned when one does an expand on it.
- interval Integer
- The interval for recurrence. For a quarterly review, the interval is 3 for type : absoluteMonthly.
- justification
Required BooleanOn Approval - Flag to indicate whether the reviewer is required to pass justification when recording a decision.
- mail
Notifications BooleanEnabled - Flag to indicate whether sending mails to reviewers and the review creator is enabled.
- number
Of IntegerOccurrences - The number of times to repeat the access review. Required and must be positive if type is numbered.
- recommendation
Look StringBack Duration - Recommendations for access reviews are calculated by looking back at 30 days of data(w.r.t the start date of the review) by default. However, in some scenarios, customers want to change how far back to look at and want to configure 60 days, 90 days, etc. instead. This setting allows customers to configure this duration. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- recommendations
Enabled Boolean - Flag to indicate whether showing recommendations to reviewers is enabled.
- reminder
Notifications BooleanEnabled - Flag to indicate whether sending reminder emails to reviewers are enabled.
- reviewers
List<Access
Review Reviewer> - This is the collection of reviewers.
- schedule
Definition StringId - The id of the access review schedule definition.
- start
Date String - The DateTime when the review is scheduled to be start. This could be a date in the future. Required on create.
- type
String | Access
Review Recurrence Range Type - The recurrence range type. The possible values are: endDate, noEnd, numbered.
- auto
Apply booleanDecisions Enabled - Flag to indicate whether auto-apply capability, to automatically change the target object access resource, is enabled. If not enabled, a user must, after the review completes, apply the access review.
- backup
Reviewers AccessReview Reviewer[] - This is the collection of backup reviewers.
- default
Decision string | DefaultDecision Type - This specifies the behavior for the autoReview feature when an access review completes.
- default
Decision booleanEnabled - Flag to indicate whether reviewers are required to provide a justification when reviewing access.
- description
For stringAdmins - The description provided by the access review creator and visible to admins.
- description
For stringReviewers - The description provided by the access review creator to be shown to reviewers.
- display
Name string - The display name for the schedule definition.
- end
Date string - The DateTime when the review is scheduled to end. Required if type is endDate
- exclude
Resource stringId - This is used to indicate the resource id(s) to exclude
- exclude
Role stringDefinition Id - This is used to indicate the role definition id(s) to exclude
- expand
Nested booleanMemberships - Flag to indicate whether to expand nested memberships or not.
- inactive
Duration string - Duration users are inactive for. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- include
Access booleanBelow Resource - Flag to indicate whether to expand nested memberships or not.
- include
Inherited booleanAccess - Flag to indicate whether to expand nested memberships or not.
- instance
Duration numberIn Days - The duration in days for an instance.
- instances
Access
Review Instance[] - This is the collection of instances returned when one does an expand on it.
- interval number
- The interval for recurrence. For a quarterly review, the interval is 3 for type : absoluteMonthly.
- justification
Required booleanOn Approval - Flag to indicate whether the reviewer is required to pass justification when recording a decision.
- mail
Notifications booleanEnabled - Flag to indicate whether sending mails to reviewers and the review creator is enabled.
- number
Of numberOccurrences - The number of times to repeat the access review. Required and must be positive if type is numbered.
- recommendation
Look stringBack Duration - Recommendations for access reviews are calculated by looking back at 30 days of data(w.r.t the start date of the review) by default. However, in some scenarios, customers want to change how far back to look at and want to configure 60 days, 90 days, etc. instead. This setting allows customers to configure this duration. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- recommendations
Enabled boolean - Flag to indicate whether showing recommendations to reviewers is enabled.
- reminder
Notifications booleanEnabled - Flag to indicate whether sending reminder emails to reviewers are enabled.
- reviewers
Access
Review Reviewer[] - This is the collection of reviewers.
- schedule
Definition stringId - The id of the access review schedule definition.
- start
Date string - The DateTime when the review is scheduled to be start. This could be a date in the future. Required on create.
- type
string | Access
Review Recurrence Range Type - The recurrence range type. The possible values are: endDate, noEnd, numbered.
- auto_
apply_ booldecisions_ enabled - Flag to indicate whether auto-apply capability, to automatically change the target object access resource, is enabled. If not enabled, a user must, after the review completes, apply the access review.
- backup_
reviewers Sequence[AccessReview Reviewer Args] - This is the collection of backup reviewers.
- default_
decision str | DefaultDecision Type - This specifies the behavior for the autoReview feature when an access review completes.
- default_
decision_ boolenabled - Flag to indicate whether reviewers are required to provide a justification when reviewing access.
- description_
for_ stradmins - The description provided by the access review creator and visible to admins.
- description_
for_ strreviewers - The description provided by the access review creator to be shown to reviewers.
- display_
name str - The display name for the schedule definition.
- end_
date str - The DateTime when the review is scheduled to end. Required if type is endDate
- exclude_
resource_ strid - This is used to indicate the resource id(s) to exclude
- exclude_
role_ strdefinition_ id - This is used to indicate the role definition id(s) to exclude
- expand_
nested_ boolmemberships - Flag to indicate whether to expand nested memberships or not.
- inactive_
duration str - Duration users are inactive for. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- include_
access_ boolbelow_ resource - Flag to indicate whether to expand nested memberships or not.
- include_
inherited_ boolaccess - Flag to indicate whether to expand nested memberships or not.
- instance_
duration_ intin_ days - The duration in days for an instance.
- instances
Sequence[Access
Review Instance Args] - This is the collection of instances returned when one does an expand on it.
- interval int
- The interval for recurrence. For a quarterly review, the interval is 3 for type : absoluteMonthly.
- justification_
required_ boolon_ approval - Flag to indicate whether the reviewer is required to pass justification when recording a decision.
- mail_
notifications_ boolenabled - Flag to indicate whether sending mails to reviewers and the review creator is enabled.
- number_
of_ intoccurrences - The number of times to repeat the access review. Required and must be positive if type is numbered.
- recommendation_
look_ strback_ duration - Recommendations for access reviews are calculated by looking back at 30 days of data(w.r.t the start date of the review) by default. However, in some scenarios, customers want to change how far back to look at and want to configure 60 days, 90 days, etc. instead. This setting allows customers to configure this duration. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- recommendations_
enabled bool - Flag to indicate whether showing recommendations to reviewers is enabled.
- reminder_
notifications_ boolenabled - Flag to indicate whether sending reminder emails to reviewers are enabled.
- reviewers
Sequence[Access
Review Reviewer Args] - This is the collection of reviewers.
- schedule_
definition_ strid - The id of the access review schedule definition.
- start_
date str - The DateTime when the review is scheduled to be start. This could be a date in the future. Required on create.
- type
str | Access
Review Recurrence Range Type - The recurrence range type. The possible values are: endDate, noEnd, numbered.
- auto
Apply BooleanDecisions Enabled - Flag to indicate whether auto-apply capability, to automatically change the target object access resource, is enabled. If not enabled, a user must, after the review completes, apply the access review.
- backup
Reviewers List<Property Map> - This is the collection of backup reviewers.
- default
Decision String | "Approve" | "Deny" | "Recommendation" - This specifies the behavior for the autoReview feature when an access review completes.
- default
Decision BooleanEnabled - Flag to indicate whether reviewers are required to provide a justification when reviewing access.
- description
For StringAdmins - The description provided by the access review creator and visible to admins.
- description
For StringReviewers - The description provided by the access review creator to be shown to reviewers.
- display
Name String - The display name for the schedule definition.
- end
Date String - The DateTime when the review is scheduled to end. Required if type is endDate
- exclude
Resource StringId - This is used to indicate the resource id(s) to exclude
- exclude
Role StringDefinition Id - This is used to indicate the role definition id(s) to exclude
- expand
Nested BooleanMemberships - Flag to indicate whether to expand nested memberships or not.
- inactive
Duration String - Duration users are inactive for. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- include
Access BooleanBelow Resource - Flag to indicate whether to expand nested memberships or not.
- include
Inherited BooleanAccess - Flag to indicate whether to expand nested memberships or not.
- instance
Duration NumberIn Days - The duration in days for an instance.
- instances List<Property Map>
- This is the collection of instances returned when one does an expand on it.
- interval Number
- The interval for recurrence. For a quarterly review, the interval is 3 for type : absoluteMonthly.
- justification
Required BooleanOn Approval - Flag to indicate whether the reviewer is required to pass justification when recording a decision.
- mail
Notifications BooleanEnabled - Flag to indicate whether sending mails to reviewers and the review creator is enabled.
- number
Of NumberOccurrences - The number of times to repeat the access review. Required and must be positive if type is numbered.
- recommendation
Look StringBack Duration - Recommendations for access reviews are calculated by looking back at 30 days of data(w.r.t the start date of the review) by default. However, in some scenarios, customers want to change how far back to look at and want to configure 60 days, 90 days, etc. instead. This setting allows customers to configure this duration. The value should be in ISO 8601 format (http://en.wikipedia.org/wiki/ISO_8601#Durations).This code can be used to convert TimeSpan to a valid interval string: XmlConvert.ToString(new TimeSpan(hours, minutes, seconds))
- recommendations
Enabled Boolean - Flag to indicate whether showing recommendations to reviewers is enabled.
- reminder
Notifications BooleanEnabled - Flag to indicate whether sending reminder emails to reviewers are enabled.
- reviewers List<Property Map>
- This is the collection of reviewers.
- schedule
Definition StringId - The id of the access review schedule definition.
- start
Date String - The DateTime when the review is scheduled to be start. This could be a date in the future. Required on create.
- type
String | "end
Date" | "no End" | "numbered" - The recurrence range type. The possible values are: endDate, noEnd, numbered.
Outputs
All input properties are implicitly available as output properties. Additionally, the AccessReviewScheduleDefinitionById resource produces the following output properties:
- Assignment
State string - The role assignment state eligible/active to review
- Id string
- The provider-assigned unique ID for this managed resource.
- Name string
- The access review schedule definition unique id.
- Principal
Id string - The identity id
- Principal
Name string - The identity display name
- Principal
Type string - The identity type user/servicePrincipal to review
- Resource
Id string - ResourceId in which this review is getting created
- Reviewers
Type string - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- Role
Definition stringId - This is used to indicate the role being reviewed
- Status string
- This read-only field specifies the status of an accessReview.
- User
Principal stringName - The user principal name(if valid)
- Assignment
State string - The role assignment state eligible/active to review
- Id string
- The provider-assigned unique ID for this managed resource.
- Name string
- The access review schedule definition unique id.
- Principal
Id string - The identity id
- Principal
Name string - The identity display name
- Principal
Type string - The identity type user/servicePrincipal to review
- Resource
Id string - ResourceId in which this review is getting created
- Reviewers
Type string - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- Role
Definition stringId - This is used to indicate the role being reviewed
- Status string
- This read-only field specifies the status of an accessReview.
- User
Principal stringName - The user principal name(if valid)
- assignment
State String - The role assignment state eligible/active to review
- id String
- The provider-assigned unique ID for this managed resource.
- name String
- The access review schedule definition unique id.
- principal
Id String - The identity id
- principal
Name String - The identity display name
- principal
Type String - The identity type user/servicePrincipal to review
- resource
Id String - ResourceId in which this review is getting created
- reviewers
Type String - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- role
Definition StringId - This is used to indicate the role being reviewed
- status String
- This read-only field specifies the status of an accessReview.
- user
Principal StringName - The user principal name(if valid)
- assignment
State string - The role assignment state eligible/active to review
- id string
- The provider-assigned unique ID for this managed resource.
- name string
- The access review schedule definition unique id.
- principal
Id string - The identity id
- principal
Name string - The identity display name
- principal
Type string - The identity type user/servicePrincipal to review
- resource
Id string - ResourceId in which this review is getting created
- reviewers
Type string - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- role
Definition stringId - This is used to indicate the role being reviewed
- status string
- This read-only field specifies the status of an accessReview.
- user
Principal stringName - The user principal name(if valid)
- assignment_
state str - The role assignment state eligible/active to review
- id str
- The provider-assigned unique ID for this managed resource.
- name str
- The access review schedule definition unique id.
- principal_
id str - The identity id
- principal_
name str - The identity display name
- principal_
type str - The identity type user/servicePrincipal to review
- resource_
id str - ResourceId in which this review is getting created
- reviewers_
type str - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- role_
definition_ strid - This is used to indicate the role being reviewed
- status str
- This read-only field specifies the status of an accessReview.
- user_
principal_ strname - The user principal name(if valid)
- assignment
State String - The role assignment state eligible/active to review
- id String
- The provider-assigned unique ID for this managed resource.
- name String
- The access review schedule definition unique id.
- principal
Id String - The identity id
- principal
Name String - The identity display name
- principal
Type String - The identity type user/servicePrincipal to review
- resource
Id String - ResourceId in which this review is getting created
- reviewers
Type String - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- role
Definition StringId - This is used to indicate the role being reviewed
- status String
- This read-only field specifies the status of an accessReview.
- user
Principal StringName - The user principal name(if valid)
Supporting Types
AccessReviewInstance, AccessReviewInstanceArgs
- Backup
Reviewers List<Pulumi.Azure Native. Authorization. Inputs. Access Review Reviewer> - This is the collection of backup reviewers.
- End
Date stringTime - The DateTime when the review instance is scheduled to end.
- Reviewers
List<Pulumi.
Azure Native. Authorization. Inputs. Access Review Reviewer> - This is the collection of reviewers.
- Start
Date stringTime - The DateTime when the review instance is scheduled to be start.
- Backup
Reviewers []AccessReview Reviewer - This is the collection of backup reviewers.
- End
Date stringTime - The DateTime when the review instance is scheduled to end.
- Reviewers
[]Access
Review Reviewer - This is the collection of reviewers.
- Start
Date stringTime - The DateTime when the review instance is scheduled to be start.
- backup
Reviewers List<AccessReview Reviewer> - This is the collection of backup reviewers.
- end
Date StringTime - The DateTime when the review instance is scheduled to end.
- reviewers
List<Access
Review Reviewer> - This is the collection of reviewers.
- start
Date StringTime - The DateTime when the review instance is scheduled to be start.
- backup
Reviewers AccessReview Reviewer[] - This is the collection of backup reviewers.
- end
Date stringTime - The DateTime when the review instance is scheduled to end.
- reviewers
Access
Review Reviewer[] - This is the collection of reviewers.
- start
Date stringTime - The DateTime when the review instance is scheduled to be start.
- backup_
reviewers Sequence[AccessReview Reviewer] - This is the collection of backup reviewers.
- end_
date_ strtime - The DateTime when the review instance is scheduled to end.
- reviewers
Sequence[Access
Review Reviewer] - This is the collection of reviewers.
- start_
date_ strtime - The DateTime when the review instance is scheduled to be start.
- backup
Reviewers List<Property Map> - This is the collection of backup reviewers.
- end
Date StringTime - The DateTime when the review instance is scheduled to end.
- reviewers List<Property Map>
- This is the collection of reviewers.
- start
Date StringTime - The DateTime when the review instance is scheduled to be start.
AccessReviewInstanceResponse, AccessReviewInstanceResponseArgs
- Id string
- The access review instance id.
- Name string
- The access review instance name.
- Reviewers
Type string - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- Status string
- This read-only field specifies the status of an access review instance.
- Type string
- The resource type.
- Backup
Reviewers List<Pulumi.Azure Native. Authorization. Inputs. Access Review Reviewer Response> - This is the collection of backup reviewers.
- End
Date stringTime - The DateTime when the review instance is scheduled to end.
- Reviewers
List<Pulumi.
Azure Native. Authorization. Inputs. Access Review Reviewer Response> - This is the collection of reviewers.
- Start
Date stringTime - The DateTime when the review instance is scheduled to be start.
- Id string
- The access review instance id.
- Name string
- The access review instance name.
- Reviewers
Type string - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- Status string
- This read-only field specifies the status of an access review instance.
- Type string
- The resource type.
- Backup
Reviewers []AccessReview Reviewer Response - This is the collection of backup reviewers.
- End
Date stringTime - The DateTime when the review instance is scheduled to end.
- Reviewers
[]Access
Review Reviewer Response - This is the collection of reviewers.
- Start
Date stringTime - The DateTime when the review instance is scheduled to be start.
- id String
- The access review instance id.
- name String
- The access review instance name.
- reviewers
Type String - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- status String
- This read-only field specifies the status of an access review instance.
- type String
- The resource type.
- backup
Reviewers List<AccessReview Reviewer Response> - This is the collection of backup reviewers.
- end
Date StringTime - The DateTime when the review instance is scheduled to end.
- reviewers
List<Access
Review Reviewer Response> - This is the collection of reviewers.
- start
Date StringTime - The DateTime when the review instance is scheduled to be start.
- id string
- The access review instance id.
- name string
- The access review instance name.
- reviewers
Type string - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- status string
- This read-only field specifies the status of an access review instance.
- type string
- The resource type.
- backup
Reviewers AccessReview Reviewer Response[] - This is the collection of backup reviewers.
- end
Date stringTime - The DateTime when the review instance is scheduled to end.
- reviewers
Access
Review Reviewer Response[] - This is the collection of reviewers.
- start
Date stringTime - The DateTime when the review instance is scheduled to be start.
- id str
- The access review instance id.
- name str
- The access review instance name.
- reviewers_
type str - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- status str
- This read-only field specifies the status of an access review instance.
- type str
- The resource type.
- backup_
reviewers Sequence[AccessReview Reviewer Response] - This is the collection of backup reviewers.
- end_
date_ strtime - The DateTime when the review instance is scheduled to end.
- reviewers
Sequence[Access
Review Reviewer Response] - This is the collection of reviewers.
- start_
date_ strtime - The DateTime when the review instance is scheduled to be start.
- id String
- The access review instance id.
- name String
- The access review instance name.
- reviewers
Type String - This field specifies the type of reviewers for a review. Usually for a review, reviewers are explicitly assigned. However, in some cases, the reviewers may not be assigned and instead be chosen dynamically. For example managers review or self review.
- status String
- This read-only field specifies the status of an access review instance.
- type String
- The resource type.
- backup
Reviewers List<Property Map> - This is the collection of backup reviewers.
- end
Date StringTime - The DateTime when the review instance is scheduled to end.
- reviewers List<Property Map>
- This is the collection of reviewers.
- start
Date StringTime - The DateTime when the review instance is scheduled to be start.
AccessReviewRecurrenceRangeType, AccessReviewRecurrenceRangeTypeArgs
- End
Date - endDate
- No
End - noEnd
- Numbered
- numbered
- Access
Review Recurrence Range Type End Date - endDate
- Access
Review Recurrence Range Type No End - noEnd
- Access
Review Recurrence Range Type Numbered - numbered
- End
Date - endDate
- No
End - noEnd
- Numbered
- numbered
- End
Date - endDate
- No
End - noEnd
- Numbered
- numbered
- END_DATE
- endDate
- NO_END
- noEnd
- NUMBERED
- numbered
- "end
Date" - endDate
- "no
End" - noEnd
- "numbered"
- numbered
AccessReviewReviewer, AccessReviewReviewerArgs
- Principal
Id string - The id of the reviewer(user/servicePrincipal)
- Principal
Id string - The id of the reviewer(user/servicePrincipal)
- principal
Id String - The id of the reviewer(user/servicePrincipal)
- principal
Id string - The id of the reviewer(user/servicePrincipal)
- principal_
id str - The id of the reviewer(user/servicePrincipal)
- principal
Id String - The id of the reviewer(user/servicePrincipal)
AccessReviewReviewerResponse, AccessReviewReviewerResponseArgs
- Principal
Type string - The identity type : user/servicePrincipal
- Principal
Id string - The id of the reviewer(user/servicePrincipal)
- Principal
Type string - The identity type : user/servicePrincipal
- Principal
Id string - The id of the reviewer(user/servicePrincipal)
- principal
Type String - The identity type : user/servicePrincipal
- principal
Id String - The id of the reviewer(user/servicePrincipal)
- principal
Type string - The identity type : user/servicePrincipal
- principal
Id string - The id of the reviewer(user/servicePrincipal)
- principal_
type str - The identity type : user/servicePrincipal
- principal_
id str - The id of the reviewer(user/servicePrincipal)
- principal
Type String - The identity type : user/servicePrincipal
- principal
Id String - The id of the reviewer(user/servicePrincipal)
DefaultDecisionType, DefaultDecisionTypeArgs
- Approve
- Approve
- Deny
- Deny
- Recommendation
- Recommendation
- Default
Decision Type Approve - Approve
- Default
Decision Type Deny - Deny
- Default
Decision Type Recommendation - Recommendation
- Approve
- Approve
- Deny
- Deny
- Recommendation
- Recommendation
- Approve
- Approve
- Deny
- Deny
- Recommendation
- Recommendation
- APPROVE
- Approve
- DENY
- Deny
- RECOMMENDATION
- Recommendation
- "Approve"
- Approve
- "Deny"
- Deny
- "Recommendation"
- Recommendation
Package Details
- Repository
- Azure Native pulumi/pulumi-azure-native
- License
- Apache-2.0