New-SAIUserConditionDefinition
SYNOPSIS
Defines the user grant of a policy
SYNTAX
InId (Default)
New-SAIUserConditionDefinition -id <String[]> [-ConditionDefinition <PSObject[]>] [<CommonParameters>]
InRole
New-SAIUserConditionDefinition -roleId <String[]> [-ConditionDefinition <PSObject[]>]
[<CommonParameters>]
Any
New-SAIUserConditionDefinition [-Any] [-ConditionDefinition <PSObject[]>] [<CommonParameters>]
DESCRIPTION
Defines a match group for a policy’s -user grant - the users an agent may act on behalf of. Match by
user identifier, by role identifier, or with a wildcard matching any user.
Only valid on an ON_BEHALF_OF policy; an AUTONOMOUS policy must have no user grant.
Groups are combined with or by the service, so pass a previous definition to
-ConditionDefinition to widen the grant.
EXAMPLES
Example 1
New-SAIUserConditionDefinition -roleId finance-analysts
Matches users holding a role
Example 2
$Users = New-SAIUserConditionDefinition -roleId finance-analysts
$Users = New-SAIUserConditionDefinition -id $NamedUserId -ConditionDefinition $Users
Matches a role or a named user
Example 3
New-SAIUserConditionDefinition -Any
Matches any user
PARAMETERS
-id
The user identifiers to match.
Type: String[]
Parameter Sets: InId
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-roleId
The role identifiers to match.
Type: String[]
Parameter Sets: InRole
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-Any
Match any user.
Type: SwitchParameter
Parameter Sets: Any
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-ConditionDefinition
An existing condition definition to add this group to.
Type: PSObject[]
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.