Organization Policy API, gRPC: AuthenticationPolicyRuleService.Get
Returns the specified authentication policy rule.
gRPC request
rpc Get (GetRuleRequest) returns (AuthenticationPolicyRule)
GetRuleRequest
{
"rule_id": "string"
}
|
Field |
Description |
|
rule_id |
string Required field. ID of the authentication policy rule to retrieve. The maximum string length in characters is 50. |
AuthenticationPolicyRule
{
"id": "string",
"name": "string",
"description": "string",
"organization_id": "string",
"effect": "Effect",
"obligations": [
{
// Includes only one of the fields `step_up_required`, `skip_mfa`, `reauthentication_required`
"step_up_required": {
"acr_id": "string",
"ttl": "google.protobuf.Duration"
},
"skip_mfa": {
"require_once": "bool"
},
"reauthentication_required": {
"ttl": "google.protobuf.Duration"
}
// end of the list of possible fields
}
],
"created_at": "google.protobuf.Timestamp",
"updated_at": "google.protobuf.Timestamp",
"subjects_include": [
"string"
],
"subjects_exclude": [
"string"
],
"networks_include": [
"string"
],
"networks_exclude": [
"string"
],
"applications_exclude": [
"string"
],
"applications_include": [
"string"
],
"status": "Status",
"labels": "map<string, string>"
}
|
Field |
Description |
|
id |
string ID of the authentication policy rule. |
|
name |
string Name of the authentication policy rule. |
|
description |
string Description of an authentication policy rule. 0-256 characters long. |
|
organization_id |
string ID of the organization that the authentication policy rule belongs to. |
|
effect |
enum Effect Effect to apply when the rule matches.
|
|
obligations[] |
Obligations to satisfy when the effect is ALLOW_WITH_OBLIGATIONS. |
|
created_at |
Creation timestamp. |
|
updated_at |
Modification timestamp. |
|
subjects_include[] |
string List of IDs of subjects affected by the authentication policy rule. |
|
subjects_exclude[] |
string List of IDs of subjects not affected by the authentication policy rule. |
|
networks_include[] |
string Source IP ranges in CIDR notation that the authentication policy rule applies to. |
|
networks_exclude[] |
string Source IP ranges in CIDR notation excluded from the authentication policy rule. |
|
applications_exclude[] |
string List of IDs of applications not affected by the authentication policy rule. |
|
applications_include[] |
string List of IDs of applications affected by the authentication policy rule. |
|
status |
enum Status Status of the authentication policy rule.
|
|
labels |
object (map<string, string>) Labels of the authentication policy rule. |
Obligation
|
Field |
Description |
|
step_up_required |
Require step-up authentication. Includes only one of the fields |
|
skip_mfa |
Allow skipping the organization's current MFA requirements. Includes only one of the fields |
|
reauthentication_required |
Require full authentication again. Includes only one of the fields |
StepUpRequired
|
Field |
Description |
|
acr_id |
string Required field. ACR ID required to satisfy this obligation. The maximum string length in characters is 50. |
|
ttl |
Required field. Maximum age of a factor verification that can satisfy this obligation. |
SkipMfa
|
Field |
Description |
|
require_once |
bool If true, the organization's current MFA requirements must have been satisfied at least once |
ReauthenticationRequired
|
Field |
Description |
|
ttl |
Required field. Maximum age of an authentication that can satisfy this obligation. |