Assignment
Security Assignment on a resource group over a given scope API Version: 2021-08-01-preview.
Example Usage
Define a default standard assignment
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using AzureNative = Pulumi.AzureNative;
return await Deployment.RunAsync(() =>
{
var assignment = new AzureNative.Security.Assignment("assignment", new()
{
AssignedStandard = new AzureNative.Security.Inputs.AssignedStandardItemArgs
{
Id = "/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
},
AssignmentId = "1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
Description = "Set of policies monitored by Azure Security Center for cross cloud",
DisplayName = "ASC Default",
Effect = "audit",
ResourceGroupName = "myResourceGroup",
Scope = "/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg",
});
});
Content copied to clipboard
package main
import (
security "github.com/pulumi/pulumi-azure-native-sdk/security"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := security.NewAssignment(ctx, "assignment", &security.AssignmentArgs{
AssignedStandard: &security.AssignedStandardItemArgs{
Id: pulumi.String("/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
},
AssignmentId: pulumi.String("1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
Description: pulumi.String("Set of policies monitored by Azure Security Center for cross cloud"),
DisplayName: pulumi.String("ASC Default"),
Effect: pulumi.String("audit"),
ResourceGroupName: pulumi.String("myResourceGroup"),
Scope: pulumi.String("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg"),
})
if err != nil {
return err
}
return nil
})
}
Content copied to clipboard
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azurenative.security.Assignment;
import com.pulumi.azurenative.security.AssignmentArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var assignment = new Assignment("assignment", AssignmentArgs.builder()
.assignedStandard(Map.of("id", "/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8"))
.assignmentId("1f3afdf9-d0c9-4c3d-847f-89da613e70a8")
.description("Set of policies monitored by Azure Security Center for cross cloud")
.displayName("ASC Default")
.effect("audit")
.resourceGroupName("myResourceGroup")
.scope("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg")
.build());
}
}
Content copied to clipboard
Exempt Recommendation From standard and resource
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using AzureNative = Pulumi.AzureNative;
return await Deployment.RunAsync(() =>
{
var assignment = new AzureNative.Security.Assignment("assignment", new()
{
AdditionalData = new AzureNative.Security.Inputs.AssignmentPropertiesAdditionalDataArgs
{
ExemptionCategory = "waiver",
},
AssignedComponent = new AzureNative.Security.Inputs.AssignedComponentItemArgs
{
Key = "1195afff-c881-495e-9bc5-1486211ae03f",
},
AssignedStandard = new AzureNative.Security.Inputs.AssignedStandardItemArgs
{
Id = "/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
},
AssignmentId = "1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
Description = "Set of policies monitored by Azure Security Center for cross cloud",
DisplayName = "ASC Default",
Effect = "Exempt",
ExpiresOn = "2022-05-01T19:50:47.083633Z",
Metadata =
{
{ "ticketId", 12345 },
},
ResourceGroupName = "myResourceGroup",
Scope = "/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg",
});
});
Content copied to clipboard
package main
import (
security "github.com/pulumi/pulumi-azure-native-sdk/security"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := security.NewAssignment(ctx, "assignment", &security.AssignmentArgs{
AdditionalData: &security.AssignmentPropertiesAdditionalDataArgs{
ExemptionCategory: pulumi.String("waiver"),
},
AssignedComponent: &security.AssignedComponentItemArgs{
Key: pulumi.String("1195afff-c881-495e-9bc5-1486211ae03f"),
},
AssignedStandard: &security.AssignedStandardItemArgs{
Id: pulumi.String("/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
},
AssignmentId: pulumi.String("1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
Description: pulumi.String("Set of policies monitored by Azure Security Center for cross cloud"),
DisplayName: pulumi.String("ASC Default"),
Effect: pulumi.String("Exempt"),
ExpiresOn: pulumi.String("2022-05-01T19:50:47.083633Z"),
Metadata: pulumi.Any{
TicketId: 12345,
},
ResourceGroupName: pulumi.String("myResourceGroup"),
Scope: pulumi.String("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg"),
})
if err != nil {
return err
}
return nil
})
}
Content copied to clipboard
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azurenative.security.Assignment;
import com.pulumi.azurenative.security.AssignmentArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var assignment = new Assignment("assignment", AssignmentArgs.builder()
.additionalData(Map.of("exemptionCategory", "waiver"))
.assignedComponent(Map.of("key", "1195afff-c881-495e-9bc5-1486211ae03f"))
.assignedStandard(Map.of("id", "/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8"))
.assignmentId("1f3afdf9-d0c9-4c3d-847f-89da613e70a8")
.description("Set of policies monitored by Azure Security Center for cross cloud")
.displayName("ASC Default")
.effect("Exempt")
.expiresOn("2022-05-01T19:50:47.083633Z")
.metadata(Map.of("ticketId", 12345))
.resourceGroupName("myResourceGroup")
.scope("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg")
.build());
}
}
Content copied to clipboard
Import
An existing resource can be imported using its type token, name, and identifier, e.g.
$ pulumi import azure-native:security:Assignment 1f3afdf9-d0c9-4c3d-847f-89da613e70a8 subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myResourceGroup/providers/Microsoft.Security/assignments/1f3afdf9-d0c9-4c3d-847f-89da613e70a8
Content copied to clipboard