Set-SAIPolicy

Set-SAIPolicy

SYNOPSIS

Updates a Secure AI access policy

SYNTAX

Set-SAIPolicy -policyId <String> [-name <String>] [-state <String>] [-agent <PSObject[]>]
 [-resources <PSObject[]>] [-description <String>] [-tags <Hashtable>] [-owners <PSObject[]>]
 [-user <PSObject[]>] [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Updates a Secure AI access policy. Omitted values are left unchanged by the service, so supply only what is changing.

accessType is fixed at creation and cannot be changed. Any -user grant supplied must stay consistent with it: an ON_BEHALF_OF policy cannot have its user grant removed, and an AUTONOMOUS policy must not be given one.

This endpoint is a Beta API and requires a resource-specific Accept header, which the module sends for you.

EXAMPLES

Example 1

Set-SAIPolicy -policyId 3f4e5d6c-7b8a-4c9d-a1e2-f3b4c5d6e7f8 -state DISABLED

Disables a policy

Example 2

Set-SAIPolicy -policyId $policyId -resources (New-SAIResourceConditionDefinition -matchId 'mcp:reporting:read-*')

Narrows the resources a policy grants

Example 3

Set-SAIPolicy -policyId $policyId -name 'Analyst tooling' -tags @{ environment = 'production' }

Renames a policy and replaces its tags

PARAMETERS

-policyId

The unique identifier of the access policy.

Type: String
Parameter Sets: (All)
Aliases: id

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-name

A new name for the policy.

Type: String
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-state

Whether the policy is enforced.

Type: String
Parameter Sets: (All)
Aliases: 
Accepted values: ENABLED, DISABLED

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-agent

The agent match groups, from New-SAIAgentConditionDefinition. Replaces the current grant.

Type: PSObject[]
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-resources

The resource match groups, from New-SAIResourceConditionDefinition. Replaces the current grant.

Type: PSObject[]
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-description

A new description for the policy.

Type: String
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-tags

Key-value tags for filtering and organisation. Replaces the current tags.

Type: Hashtable
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-owners

The users or roles assigned as policy owners, from New-SAIOwnerDefinition.

Type: PSObject[]
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-user

The user match groups, from New-SAIUserConditionDefinition. Valid only for an ON_BEHALF_OF policy.

Type: PSObject[]
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

OUTPUTS

NOTES