IdentityCommand.UAP

IdentityCommand.UAP is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the Idira Access Control Policies API from within the PowerShell environment.

It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.

Access Policies

Get-UAPPolicy lists the policies on the tenant. The list carries partial details for each policy, so fetch a policy by identifier to see its targets and full configuration:

# All policies - partial details
Get-UAPPolicy

# One policy, in full
Get-UAPPolicy -policyId aws_d880e53b-151e-414b-8f07-9ea55888abc3

# Filter criteria are assembled into the service's filter expression
Get-UAPPolicy -targetCategory VM -status Active
Get-UAPPolicy -policyTags production, critical -locationType AWS, Azure

# Or pass an expression directly
Get-UAPPolicy -filter "(targetCategory eq 'VM')"

# Free text search across name and description
Get-UAPPolicy -q 'access to production'

Building a Policy

A policy is assembled from definitions - principals, conditions, and the targets for its category:

$Principals = New-UAPPrincipalDefinition -id c2c7bcc6-9560-44e0-8dff-5be221cd37ee `
    -name 'John@cyberark.cloud.28905' -type USER `
    -sourceDirectoryName 'CyberArk Cloud Directory' -sourceDirectoryId '09B9A9B0-6CE8-465F-AB03-65766D33B05E'

$Principals = New-UAPPrincipalDefinition -id $RoleId -name 'Administration Role' -type ROLE -PrincipalDefinition $Principals

$Conditions = New-UAPConditionDefinition -daysOfTheWeek 1, 2, 3, 4, 5 -fromHour '08:00:00' -toHour '17:00:00' -maxSessionDuration 1

Each target category has its own builder, and each accepts a previous definition so targets are built up in a chain:

# Cloud console - a role in an AWS account
$Targets = New-UAPCloudConsoleTargetDefinition -roleId 'arn:aws:iam::123456789123:role/examplerole' -workspaceId 123456789123

New-UAPPolicy -name 'AWS read access' -targetCategory 'Cloud Console' -locationType AWS `
    -principals $Principals -conditions $Conditions -targets $Targets
# Virtual machines - locations are added to one targets object
$Targets = New-UAPVirtualMachineTargetDefinition -AWS -regions us-east-1 -accountIds 123456789012
$Targets = New-UAPVirtualMachineTargetDefinition -Azure -subscriptions $SubscriptionId -TargetDefinition $Targets

$Behavior = New-UAPVirtualMachineBehaviorDefinition -sshUsername ec2-user -rdpAssignGroups Administrators

New-UAPPolicy -name 'Production VM access' -targetCategory VM -locationType AWS -policyTags production `
    -principals $Principals -conditions (New-UAPConditionDefinition -maxSessionDuration 2 -idleTime 10) `
    -targets $Targets -behavior $Behavior
# Databases - the profile shape follows the authentication method
$Targets = New-UAPDatabaseTargetDefinition -instanceName My-Local-MySQL -instanceType MySQL -instanceId 197012 `
    -authenticationMethod db_auth -profile @{ roles = @('hr', 'MySQL_role') }

New-UAPPolicy -name 'Database access' -targetCategory DB -locationType 'FQDN/IP' `
    -principals $Principals -conditions (New-UAPConditionDefinition -maxSessionDuration 2 -idleTime 10) -targets $Targets
# Kubernetes clusters
$Targets = New-UAPClusterTargetDefinition -roleId 'arn:aws:iam::123456789123:role/clusterexamplerole' `
    -workspaceId 123456789123 -clusterId 'arn:aws:eks:us-east-1:123456789123:cluster/example-cluster' -scope cluster -region us-east-1

New-UAPPolicy -name 'EKS cluster access' -targetCategory Clusters -locationType AWS -connectionMethod proxy `
    -principals $Principals -conditions (New-UAPConditionDefinition -maxSessionDuration 1) -targets $Targets
# Entra ID group membership
$Targets = New-UAPGroupTargetDefinition -groupId c63819e2-2397-4faa-850f-4abde34e52fb -directoryId 280a06f4-3f9b-4910-8967-053a914e314e

New-UAPPolicy -name 'Entra group membership' -targetCategory Groups -locationType Azure `
    -principals $Principals -conditions (New-UAPConditionDefinition -maxSessionDuration 2) -targets $Targets

Targets are wrapped in whatever shape the chosen category requires, so pass the builder output as it comes.

Changing and Removing a Policy

The service replaces a policy with whatever is sent to it, so Set-UAPPolicy reads the current policy first and keeps everything you do not supply. Supply only what is changing:

# Suspend a policy, leaving the rest of it alone
Set-UAPPolicy -policyId $policyId -status Suspended

# Rename it
Set-UAPPolicy -policyId $policyId -name 'AWS read access'

# Replace just its targets
Set-UAPPolicy -policyId $policyId -targets $Targets

# Suspend every active VM policy
Get-UAPPolicy -status Active -targetCategory VM | Set-UAPPolicy -status Suspended

Remove-UAPPolicy -policyId $policyId

The read-only properties the service adds to a retrieved policy - who created it, resolved target display names, the status detail behind its status - are dropped rather than echoed back. Because omitted values fall back to the current policy, a value cannot be cleared by omitting it.

Validating a Cloud Console Policy

Validation is asynchronous: a VALIDATING response means the check started, not that it passed. Read the outcome from the policy afterwards:

Test-UAPPolicy -policyId $policyId
(Get-UAPPolicy -policyId $policyId).metadata.status