Organization Policy API, gRPC: AuthenticationPolicyRuleService.List
Lists authentication policy rules in the specified organization.
gRPC request
rpc List (ListRulesRequest) returns (ListRulesResponse)
ListRulesRequest
{
"organization_id": "string",
"page_size": "int64",
"page_token": "string",
"filter": "string"
}
|
Field |
Description |
|
organization_id |
string Required field. ID of the organization to list authentication policy rules for. The maximum string length in characters is 50. |
|
page_size |
int64 Maximum number of authentication policy rules to return. Acceptable values are 0 to 1000, inclusive. |
|
page_token |
string Page token returned in ListRulesResponse.next_page_token by a previous request. The maximum string length in characters is 2000. |
|
filter |
string Filter expression applied to the returned rules. The maximum string length in characters is 1000. |
ListRulesResponse
{
"auth_policy_rules": [
{
"id": "string",
"name": "string",
"description": "string",
"organization_id": "string",
"effect": "Effect",
"obligations": [
{
// Includes only one of the fields `step_up_required`, `skip_mfa`, `reauthentication_required`
"step_up_required": {
"acr_id": "string",
"ttl": "google.protobuf.Duration"
},
"skip_mfa": {
"require_once": "bool"
},
"reauthentication_required": {
"ttl": "google.protobuf.Duration"
}
// end of the list of possible fields
}
],
"created_at": "google.protobuf.Timestamp",
"updated_at": "google.protobuf.Timestamp",
"subjects_include": [
"string"
],
"subjects_exclude": [
"string"
],
"networks_include": [
"string"
],
"networks_exclude": [
"string"
],
"applications_exclude": [
"string"
],
"applications_include": [
"string"
],
"status": "Status",
"labels": "map<string, string>"
}
],
"next_page_token": "string"
}
|
Field |
Description |
|
auth_policy_rules[] |
Authentication policy rules matching the request. |
|
next_page_token |
string Token to retrieve the next page of results. |
AuthenticationPolicyRule
|
Field |
Description |
|
id |
string ID of the authentication policy rule. |
|
name |
string Name of the authentication policy rule. |
|
description |
string Description of an authentication policy rule. 0-256 characters long. |
|
organization_id |
string ID of the organization that the authentication policy rule belongs to. |
|
effect |
enum Effect Effect to apply when the rule matches.
|
|
obligations[] |
Obligations to satisfy when the effect is ALLOW_WITH_OBLIGATIONS. |
|
created_at |
Creation timestamp. |
|
updated_at |
Modification timestamp. |
|
subjects_include[] |
string List of IDs of subjects affected by the authentication policy rule. |
|
subjects_exclude[] |
string List of IDs of subjects not affected by the authentication policy rule. |
|
networks_include[] |
string Source IP ranges in CIDR notation that the authentication policy rule applies to. |
|
networks_exclude[] |
string Source IP ranges in CIDR notation excluded from the authentication policy rule. |
|
applications_exclude[] |
string List of IDs of applications not affected by the authentication policy rule. |
|
applications_include[] |
string List of IDs of applications affected by the authentication policy rule. |
|
status |
enum Status Status of the authentication policy rule.
|
|
labels |
object (map<string, string>) Labels of the authentication policy rule. |
Obligation
|
Field |
Description |
|
step_up_required |
Require step-up authentication. Includes only one of the fields |
|
skip_mfa |
Allow skipping the organization's current MFA requirements. Includes only one of the fields |
|
reauthentication_required |
Require full authentication again. Includes only one of the fields |
StepUpRequired
|
Field |
Description |
|
acr_id |
string Required field. ACR ID required to satisfy this obligation. The maximum string length in characters is 50. |
|
ttl |
Required field. Maximum age of a factor verification that can satisfy this obligation. |
SkipMfa
|
Field |
Description |
|
require_once |
bool If true, the organization's current MFA requirements must have been satisfied at least once |
ReauthenticationRequired
|
Field |
Description |
|
ttl |
Required field. Maximum age of an authentication that can satisfy this obligation. |