Assignment
Security Assignment on a resource group over a given scope Uses Azure REST API version 2021-08-01-preview. In version 2.x of the Azure Native provider, it used API version 2021-08-01-preview.
Example Usage
Define a default standard assignment
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using AzureNative = Pulumi.AzureNative;
return await Deployment.RunAsync(() =>
{
var assignment = new AzureNative.Security.Assignment("assignment", new()
{
AssignedStandard = new AzureNative.Security.Inputs.AssignedStandardItemArgs
{
Id = "/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
},
AssignmentId = "1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
Description = "Set of policies monitored by Azure Security Center for cross cloud",
DisplayName = "ASC Default",
Effect = "audit",
ResourceGroupName = "myResourceGroup",
Scope = "/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg",
});
});
Content copied to clipboard
package main
import (
security "github.com/pulumi/pulumi-azure-native-sdk/security/v3"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := security.NewAssignment(ctx, "assignment", &security.AssignmentArgs{
AssignedStandard: &security.AssignedStandardItemArgs{
Id: pulumi.String("/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
},
AssignmentId: pulumi.String("1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
Description: pulumi.String("Set of policies monitored by Azure Security Center for cross cloud"),
DisplayName: pulumi.String("ASC Default"),
Effect: pulumi.String("audit"),
ResourceGroupName: pulumi.String("myResourceGroup"),
Scope: pulumi.String("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg"),
})
if err != nil {
return err
}
return nil
})
}
Content copied to clipboard
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azurenative.security.Assignment;
import com.pulumi.azurenative.security.AssignmentArgs;
import com.pulumi.azurenative.security.inputs.AssignedStandardItemArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var assignment = new Assignment("assignment", AssignmentArgs.builder()
.assignedStandard(AssignedStandardItemArgs.builder()
.id("/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8")
.build())
.assignmentId("1f3afdf9-d0c9-4c3d-847f-89da613e70a8")
.description("Set of policies monitored by Azure Security Center for cross cloud")
.displayName("ASC Default")
.effect("audit")
.resourceGroupName("myResourceGroup")
.scope("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg")
.build());
}
}
Content copied to clipboard
Exempt Recommendation From standard and resource
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using AzureNative = Pulumi.AzureNative;
return await Deployment.RunAsync(() =>
{
var assignment = new AzureNative.Security.Assignment("assignment", new()
{
AdditionalData = new AzureNative.Security.Inputs.AssignmentPropertiesAdditionalDataArgs
{
ExemptionCategory = "waiver",
},
AssignedComponent = new AzureNative.Security.Inputs.AssignedComponentItemArgs
{
Key = "1195afff-c881-495e-9bc5-1486211ae03f",
},
AssignedStandard = new AzureNative.Security.Inputs.AssignedStandardItemArgs
{
Id = "/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
},
AssignmentId = "1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
Description = "Set of policies monitored by Azure Security Center for cross cloud",
DisplayName = "ASC Default",
Effect = "Exempt",
ExpiresOn = "2022-05-01T19:50:47.083633Z",
Metadata = new Dictionary<string, object?>
{
["ticketId"] = 12345,
},
ResourceGroupName = "myResourceGroup",
Scope = "/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg",
});
});
Content copied to clipboard
package main
import (
security "github.com/pulumi/pulumi-azure-native-sdk/security/v3"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := security.NewAssignment(ctx, "assignment", &security.AssignmentArgs{
AdditionalData: &security.AssignmentPropertiesAdditionalDataArgs{
ExemptionCategory: pulumi.String("waiver"),
},
AssignedComponent: &security.AssignedComponentItemArgs{
Key: pulumi.String("1195afff-c881-495e-9bc5-1486211ae03f"),
},
AssignedStandard: &security.AssignedStandardItemArgs{
Id: pulumi.String("/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
},
AssignmentId: pulumi.String("1f3afdf9-d0c9-4c3d-847f-89da613e70a8"),
Description: pulumi.String("Set of policies monitored by Azure Security Center for cross cloud"),
DisplayName: pulumi.String("ASC Default"),
Effect: pulumi.String("Exempt"),
ExpiresOn: pulumi.String("2022-05-01T19:50:47.083633Z"),
Metadata: pulumi.Any(map[string]interface{}{
"ticketId": 12345,
}),
ResourceGroupName: pulumi.String("myResourceGroup"),
Scope: pulumi.String("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg"),
})
if err != nil {
return err
}
return nil
})
}
Content copied to clipboard
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azurenative.security.Assignment;
import com.pulumi.azurenative.security.AssignmentArgs;
import com.pulumi.azurenative.security.inputs.AssignmentPropertiesAdditionalDataArgs;
import com.pulumi.azurenative.security.inputs.AssignedComponentItemArgs;
import com.pulumi.azurenative.security.inputs.AssignedStandardItemArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var assignment = new Assignment("assignment", AssignmentArgs.builder()
.additionalData(AssignmentPropertiesAdditionalDataArgs.builder()
.exemptionCategory("waiver")
.build())
.assignedComponent(AssignedComponentItemArgs.builder()
.key("1195afff-c881-495e-9bc5-1486211ae03f")
.build())
.assignedStandard(AssignedStandardItemArgs.builder()
.id("/providers/Microsoft.Security/Standards/1f3afdf9-d0c9-4c3d-847f-89da613e70a8")
.build())
.assignmentId("1f3afdf9-d0c9-4c3d-847f-89da613e70a8")
.description("Set of policies monitored by Azure Security Center for cross cloud")
.displayName("ASC Default")
.effect("Exempt")
.expiresOn("2022-05-01T19:50:47.083633Z")
.metadata(Map.of("ticketId", 12345))
.resourceGroupName("myResourceGroup")
.scope("/subscriptions/ae640e6b-ba3e-4256-9d62-2993eecfa6f2/ResourceGroup/rg")
.build());
}
}
Content copied to clipboard
Import
An existing resource can be imported using its type token, name, and identifier, e.g.
$ pulumi import azure-native:security:Assignment 1f3afdf9-d0c9-4c3d-847f-89da613e70a8 /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Security/assignments/{assignmentId}
Content copied to clipboard
Properties
Link copied to clipboard
Additional data about the assignment
Link copied to clipboard
Component item with key as applied to this standard assignment over the given scope
Link copied to clipboard
Standard item with key as applied to this standard assignment over the given scope
Link copied to clipboard
The Azure API version of the resource.
Link copied to clipboard
description of the standardAssignment
Link copied to clipboard
display name of the standardAssignment
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Azure Resource Manager metadata containing createdBy and modifiedBy information.