Organization Policy API, REST: AuthenticationPolicyRule.Update
Updates the specified authentication policy rule.
HTTP request
PATCH https://organization-manager.api.cloud.yandex.net/organization-manager/v1/policy/authenticationPolicyRules/{ruleId}
Path parameters
|
Field |
Description |
|
ruleId |
string Required field. ID of authentication policy rule to update. The maximum string length in characters is 50. |
Body parameters
{
"updateMask": "string",
"name": "string",
"description": "string",
"effect": "string",
"obligations": [
{
// Includes only one of the fields `stepUpRequired`, `skipMfa`, `reauthenticationRequired`
"stepUpRequired": {
"acrId": "string",
"ttl": "string"
},
"skipMfa": {
"requireOnce": "boolean"
},
"reauthenticationRequired": {
"ttl": "string"
}
// end of the list of possible fields
}
],
"subjectsInclude": [
"string"
],
"subjectsExclude": [
"string"
],
"networksInclude": [
"string"
],
"networksExclude": [
"string"
],
"applicationsExclude": [
"string"
],
"applicationsInclude": [
"string"
],
"labels": "object"
}
|
Field |
Description |
|
updateMask |
string (field-mask) A comma-separated names off ALL fields to be updated. If |
|
name |
string Updated name of the authentication policy rule. Value must match the regular expression |
|
description |
string Updated description of the authentication policy rule. The maximum string length in characters is 256. |
|
effect |
enum (Effect) Effect to apply when the rule matches.
|
|
obligations[] |
Obligations to satisfy when the effect is ALLOW_WITH_OBLIGATIONS. The maximum number of elements is 5. |
|
subjectsInclude[] |
string List of IDs of subjects to be affected by the authentication policy rule. The maximum string length in characters for each value is 64. The maximum number of elements is 64. |
|
subjectsExclude[] |
string List of IDs of subjects not to be affected by the authentication policy rule. The maximum string length in characters for each value is 64. The maximum number of elements is 64. |
|
networksInclude[] |
string Source IP ranges in CIDR notation that the authentication policy rule applies to. The maximum string length in characters for each value is 64. The maximum number of elements is 64. |
|
networksExclude[] |
string Source IP ranges in CIDR notation excluded from the authentication policy rule. The maximum string length in characters for each value is 64. The maximum number of elements is 64. |
|
applicationsExclude[] |
string List of IDs of applications not to be affected by the authentication policy rule. The maximum string length in characters for each value is 64. The maximum number of elements is 64. |
|
applicationsInclude[] |
string List of IDs of applications to be affected by the authentication policy rule. The maximum string length in characters for each value is 64. The maximum number of elements is 64. |
|
labels |
object (map<string, string>) Labels of the authentication policy rule. The maximum string length in characters for each value is 63. The string length in characters for each key must be 1-63. Each key must match the regular expression |
Obligation
|
Field |
Description |
|
stepUpRequired |
Require step-up authentication. Includes only one of the fields |
|
skipMfa |
Allow skipping the organization's current MFA requirements. Includes only one of the fields |
|
reauthenticationRequired |
Require full authentication again. Includes only one of the fields |
StepUpRequired
|
Field |
Description |
|
acrId |
string Required field. ACR ID required to satisfy this obligation. The maximum string length in characters is 50. |
|
ttl |
string (duration) Required field. Maximum age of a factor verification that can satisfy this obligation. |
SkipMfa
|
Field |
Description |
|
requireOnce |
boolean If true, the organization's current MFA requirements must have been satisfied at least once |
ReauthenticationRequired
|
Field |
Description |
|
ttl |
string (duration) Required field. Maximum age of an authentication that can satisfy this obligation. |
Response
HTTP Code: 200 - OK
{
"id": "string",
"description": "string",
"createdAt": "string",
"createdBy": "string",
"modifiedAt": "string",
"done": "boolean",
"metadata": "object",
// Includes only one of the fields `error`, `response`
"error": {
"code": "integer",
"message": "string",
"details": [
"object"
]
},
"response": "object"
// end of the list of possible fields
}
An Operation resource. For more information, see Operation.
|
Field |
Description |
|
id |
string ID of the operation. |
|
description |
string Description of the operation. 0-256 characters long. |
|
createdAt |
string (date-time) Creation timestamp. String in RFC3339 To work with values in this field, use the APIs described in the |
|
createdBy |
string ID of the user or service account who initiated the operation. |
|
modifiedAt |
string (date-time) The time when the Operation resource was last modified. String in RFC3339 To work with values in this field, use the APIs described in the |
|
done |
boolean If the value is |
|
metadata |
object Service-specific metadata associated with the operation. |
|
error |
The error result of the operation in case of failure or cancellation. Includes only one of the fields The operation result. |
|
response |
object The normal response of the operation in case of success. Includes only one of the fields The operation result. |
Status
The error result of the operation in case of failure or cancellation.
|
Field |
Description |
|
code |
integer (int32) Error code. An enum value of google.rpc.Code |
|
message |
string An error message. |
|
details[] |
object A list of messages that carry the error details. |