Cisco ISE v0.2.1 published on Saturday, Mar 15, 2025 by Pulumi
ise.deviceadmin.getAuthorizationRule
Explore with Pulumi AI
This data source can read the Device Admin Authorization Rule.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as ise from "@pulumi/ise";
const example = ise.deviceadmin.getAuthorizationRule({
    id: "76d24097-41c4-4558-a4d0-a8c07ac08470",
    policySetId: "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
});
import pulumi
import pulumi_ise as ise
example = ise.deviceadmin.get_authorization_rule(id="76d24097-41c4-4558-a4d0-a8c07ac08470",
    policy_set_id="d82952cb-b901-4b09-b363-5ebf39bdbaf9")
package main
import (
	"github.com/pulumi/pulumi-ise/sdk/go/ise/deviceadmin"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		_, err := deviceadmin.LookupAuthorizationRule(ctx, &deviceadmin.LookupAuthorizationRuleArgs{
			Id:          pulumi.StringRef("76d24097-41c4-4558-a4d0-a8c07ac08470"),
			PolicySetId: "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
		}, nil)
		if err != nil {
			return err
		}
		return nil
	})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Ise = Pulumi.Ise;
return await Deployment.RunAsync(() => 
{
    var example = Ise.DeviceAdmin.GetAuthorizationRule.Invoke(new()
    {
        Id = "76d24097-41c4-4558-a4d0-a8c07ac08470",
        PolicySetId = "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
    });
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.ise.deviceadmin.DeviceadminFunctions;
import com.pulumi.ise.deviceadmin.inputs.GetAuthorizationRuleArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }
    public static void stack(Context ctx) {
        final var example = DeviceadminFunctions.getAuthorizationRule(GetAuthorizationRuleArgs.builder()
            .id("76d24097-41c4-4558-a4d0-a8c07ac08470")
            .policySetId("d82952cb-b901-4b09-b363-5ebf39bdbaf9")
            .build());
    }
}
variables:
  example:
    fn::invoke:
      function: ise:deviceadmin:getAuthorizationRule
      arguments:
        id: 76d24097-41c4-4558-a4d0-a8c07ac08470
        policySetId: d82952cb-b901-4b09-b363-5ebf39bdbaf9
Using getAuthorizationRule
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getAuthorizationRule(args: GetAuthorizationRuleArgs, opts?: InvokeOptions): Promise<GetAuthorizationRuleResult>
function getAuthorizationRuleOutput(args: GetAuthorizationRuleOutputArgs, opts?: InvokeOptions): Output<GetAuthorizationRuleResult>def get_authorization_rule(id: Optional[str] = None,
                           name: Optional[str] = None,
                           policy_set_id: Optional[str] = None,
                           opts: Optional[InvokeOptions] = None) -> GetAuthorizationRuleResult
def get_authorization_rule_output(id: Optional[pulumi.Input[str]] = None,
                           name: Optional[pulumi.Input[str]] = None,
                           policy_set_id: Optional[pulumi.Input[str]] = None,
                           opts: Optional[InvokeOptions] = None) -> Output[GetAuthorizationRuleResult]func LookupAuthorizationRule(ctx *Context, args *LookupAuthorizationRuleArgs, opts ...InvokeOption) (*LookupAuthorizationRuleResult, error)
func LookupAuthorizationRuleOutput(ctx *Context, args *LookupAuthorizationRuleOutputArgs, opts ...InvokeOption) LookupAuthorizationRuleResultOutput> Note: This function is named LookupAuthorizationRule in the Go SDK.
public static class GetAuthorizationRule 
{
    public static Task<GetAuthorizationRuleResult> InvokeAsync(GetAuthorizationRuleArgs args, InvokeOptions? opts = null)
    public static Output<GetAuthorizationRuleResult> Invoke(GetAuthorizationRuleInvokeArgs args, InvokeOptions? opts = null)
}public static CompletableFuture<GetAuthorizationRuleResult> getAuthorizationRule(GetAuthorizationRuleArgs args, InvokeOptions options)
public static Output<GetAuthorizationRuleResult> getAuthorizationRule(GetAuthorizationRuleArgs args, InvokeOptions options)
fn::invoke:
  function: ise:deviceadmin/getAuthorizationRule:getAuthorizationRule
  arguments:
    # arguments dictionaryThe following arguments are supported:
- PolicySet stringId 
- Policy set ID
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- PolicySet stringId 
- Policy set ID
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet stringId 
- Policy set ID
- id string
- The id of the object
- name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policy_set_ strid 
- Policy set ID
- id str
- The id of the object
- name str
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
getAuthorizationRule Result
The following output properties are available:
- Childrens
List<GetAuthorization Rule Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- CommandSets List<string>
- Command sets enforce the specified list of commands that can be executed by a device administrator
- ConditionAttribute stringName 
- Dictionary attribute name
- ConditionAttribute stringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionDictionary stringName 
- Dictionary name
- ConditionDictionary stringValue 
- Dictionary value
- ConditionId string
- UUID for condition
- ConditionIs boolNegate 
- Indicates whereas this condition is in negate mode
- ConditionOperator string
- Equality operator
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- Default bool
- Indicates if this rule is the default one
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- PolicySet stringId 
- Policy set ID
- Profile string
- Device admin profiles control the initial login session of the device administrator
- Rank int
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- State string
- The state that the rule is in. A disabled rule cannot be matched.
- Childrens
[]GetAuthorization Rule Children 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- CommandSets []string
- Command sets enforce the specified list of commands that can be executed by a device administrator
- ConditionAttribute stringName 
- Dictionary attribute name
- ConditionAttribute stringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionDictionary stringName 
- Dictionary name
- ConditionDictionary stringValue 
- Dictionary value
- ConditionId string
- UUID for condition
- ConditionIs boolNegate 
- Indicates whereas this condition is in negate mode
- ConditionOperator string
- Equality operator
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- Default bool
- Indicates if this rule is the default one
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- PolicySet stringId 
- Policy set ID
- Profile string
- Device admin profiles control the initial login session of the device administrator
- Rank int
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- State string
- The state that the rule is in. A disabled rule cannot be matched.
- childrens
List<GetAuthorization Rule Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- commandSets List<String>
- Command sets enforce the specified list of commands that can be executed by a device administrator
- conditionAttribute StringName 
- Dictionary attribute name
- conditionAttribute StringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- conditionDictionary StringName 
- Dictionary name
- conditionDictionary StringValue 
- Dictionary value
- conditionId String
- UUID for condition
- conditionIs BooleanNegate 
- Indicates whereas this condition is in negate mode
- conditionOperator String
- Equality operator
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default_ Boolean
- Indicates if this rule is the default one
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- profile String
- Device admin profiles control the initial login session of the device administrator
- rank Integer
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state String
- The state that the rule is in. A disabled rule cannot be matched.
- childrens
GetAuthorization Rule Children[] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- commandSets string[]
- Command sets enforce the specified list of commands that can be executed by a device administrator
- conditionAttribute stringName 
- Dictionary attribute name
- conditionAttribute stringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- conditionDictionary stringName 
- Dictionary name
- conditionDictionary stringValue 
- Dictionary value
- conditionId string
- UUID for condition
- conditionIs booleanNegate 
- Indicates whereas this condition is in negate mode
- conditionOperator string
- Equality operator
- conditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default boolean
- Indicates if this rule is the default one
- id string
- The id of the object
- name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet stringId 
- Policy set ID
- profile string
- Device admin profiles control the initial login session of the device administrator
- rank number
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state string
- The state that the rule is in. A disabled rule cannot be matched.
- childrens
Sequence[GetAuthorization Rule Children] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- command_sets Sequence[str]
- Command sets enforce the specified list of commands that can be executed by a device administrator
- condition_attribute_ strname 
- Dictionary attribute name
- condition_attribute_ strvalue 
- Attribute value for condition. Value type is specified in dictionary object.
- condition_dictionary_ strname 
- Dictionary name
- condition_dictionary_ strvalue 
- Dictionary value
- condition_id str
- UUID for condition
- condition_is_ boolnegate 
- Indicates whereas this condition is in negate mode
- condition_operator str
- Equality operator
- condition_type str
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default bool
- Indicates if this rule is the default one
- id str
- The id of the object
- name str
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policy_set_ strid 
- Policy set ID
- profile str
- Device admin profiles control the initial login session of the device administrator
- rank int
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state str
- The state that the rule is in. A disabled rule cannot be matched.
- childrens List<Property Map>
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- commandSets List<String>
- Command sets enforce the specified list of commands that can be executed by a device administrator
- conditionAttribute StringName 
- Dictionary attribute name
- conditionAttribute StringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- conditionDictionary StringName 
- Dictionary name
- conditionDictionary StringValue 
- Dictionary value
- conditionId String
- UUID for condition
- conditionIs BooleanNegate 
- Indicates whereas this condition is in negate mode
- conditionOperator String
- Equality operator
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default Boolean
- Indicates if this rule is the default one
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- profile String
- Device admin profiles control the initial login session of the device administrator
- rank Number
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state String
- The state that the rule is in. A disabled rule cannot be matched.
Supporting Types
GetAuthorizationRuleChildren   
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- Childrens
List<GetAuthorization Rule Children Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- Childrens
[]GetAuthorization Rule Children Children 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- childrens
List<GetAuthorization Rule Children Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
- attributeName string
- Dictionary attribute name
- attributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- childrens
GetAuthorization Rule Children Children[] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- conditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionaryName string
- Dictionary name
- dictionaryValue string
- Dictionary value
- id string
- UUID for condition
- isNegate boolean
- Indicates whereas this condition is in negate mode
- operator string
- Equality operator
- attribute_name str
- Dictionary attribute name
- attribute_value str
- Attribute value for condition. Value type is specified in dictionary object.
- childrens
Sequence[GetAuthorization Rule Children Children] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- condition_type str
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionary_name str
- Dictionary name
- dictionary_value str
- Dictionary value
- id str
- UUID for condition
- is_negate bool
- Indicates whereas this condition is in negate mode
- operator str
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- childrens List<Property Map>
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
GetAuthorizationRuleChildrenChildren    
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionType string
- Condition type.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionType string
- Condition type.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- conditionType String
- Condition type.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
- attributeName string
- Dictionary attribute name
- attributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- conditionType string
- Condition type.
- dictionaryName string
- Dictionary name
- dictionaryValue string
- Dictionary value
- id string
- UUID for condition
- isNegate boolean
- Indicates whereas this condition is in negate mode
- operator string
- Equality operator
- attribute_name str
- Dictionary attribute name
- attribute_value str
- Attribute value for condition. Value type is specified in dictionary object.
- condition_type str
- Condition type.
- dictionary_name str
- Dictionary name
- dictionary_value str
- Dictionary value
- id str
- UUID for condition
- is_negate bool
- Indicates whereas this condition is in negate mode
- operator str
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- conditionType String
- Condition type.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
Package Details
- Repository
- ise pulumi/pulumi-ise
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the iseTerraform Provider.
