Set-UAPPolicy
SYNOPSIS
Updates an access policy
SYNTAX
Set-UAPPolicy -policyId <String> [-name <String>] [-description <String>] [-targetCategory <String>]
[-locationType <String>] [-policyType <String>] [-policyTags <String[]>] [-timeZone <String>]
[-fromTime <DateTime>] [-toTime <DateTime>] [-status <String>] [-principals <PSObject[]>]
[-conditions <PSObject>] [-targets <PSObject>] [-behavior <PSObject>] [-connectionMethod <String>]
[-WhatIf] [-Confirm] [<CommonParameters>]
DESCRIPTION
Updates an access policy.
The service replaces the policy with the payload sent, so this command retrieves the current policy first and uses it for whatever you do not supply - supply only what is changing.
The read-only properties the service adds to a retrieved policy are dropped rather than echoed back: who created and last updated it, the status code and description behind its status, the display names it resolved for each target, its delegation classification, and the invalid resources behind an error status.
Because omitted values fall back to the current policy, a value cannot be cleared by omitting it.
Suspending or reactivating a policy is done here, with -status.
EXAMPLES
Example 1
Set-UAPPolicy -policyId aws_d880e53b-151e-414b-8f07-9ea55888abc3 -status Suspended
Suspends a policy, leaving the rest of its configuration as it is
Example 2
Set-UAPPolicy -policyId $policyId -name 'AWS read access' -description 'Read only access for the platform team'
Renames a policy and updates its description
Example 3
$Targets = New-UAPCloudConsoleTargetDefinition -roleId $FirstRole -workspaceId $Workspace
$Targets = New-UAPCloudConsoleTargetDefinition -roleId $SecondRole -workspaceId $Workspace -TargetDefinition $Targets
Set-UAPPolicy -policyId $policyId -targets $Targets
Replaces the targets of a policy, leaving everything else as it is
Example 4
Get-UAPPolicy -status Active -targetCategory VM | Set-UAPPolicy -status Suspended
Suspends every active VM policy
Example 5
Set-UAPPolicy -policyId $policyId -conditions (New-UAPConditionDefinition -maxSessionDuration 4 -idleTime 15)
Extends the maximum session duration and idle timeout
PARAMETERS
-policyId
The unique identifier of the policy to update.
Type: String
Parameter Sets: (All)
Aliases: id
Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-name
A new name for the policy. The current name is kept when not supplied.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-description
A short description of the policy, up to 200 characters.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-targetCategory
The category of target the policy grants access to. The current category is kept when not supplied.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: Cloud Console, VM, DB, Clusters, Groups
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-locationType
The location of the target. The current location is kept when not supplied.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: AWS, Azure, GCP, FQDN/IP
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-policyType
Whether the policy is recurring or on-demand. The service defaults to Recurring.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: Recurring, OnDemand
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-policyTags
Up to 20 tags used to identify the policy and those similar to it.
Type: String[]
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-timeZone
The time zone identifier the access window is evaluated in, for example Europe/London. The service defaults to GMT.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-fromTime
The date the policy becomes active. Omit both times for an unlimited timeframe.
Type: DateTime
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-toTime
The date the policy expires.
Type: DateTime
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-status
The policy status. Policies are created Active; a policy can be moved between Active and Suspended.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: Active, Suspended
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-principals
The identities the policy applies to, from New-UAPPrincipalDefinition. The current identities are kept when not supplied.
Type: PSObject[]
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-conditions
The access window and session limits, from New-UAPConditionDefinition.
Type: PSObject
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-targets
The targets the policy grants access to, from the New-UAP*TargetDefinition builder matching the target category. The current targets are kept when not supplied.
Type: PSObject
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-behavior
How policy members connect to a VM target, from New-UAPVirtualMachineBehaviorDefinition. Required for VM policies.
Type: PSObject
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-connectionMethod
How policy members connect to a cluster target. Applies to Clusters policies.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: direct, proxy
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-WhatIf
Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-Confirm
Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.