Creates a rule for Azure groups in the specified ActiveView.
New-DRAAzureGroupRule -ActiveView <String> -Name <String> [-Exclude <SwitchParameter>] [-RestrictUsageOnlyAllow <SwitchParameter>] [-RestrictUsageDoNotAllow <SwitchParameter>] [-Comment <String>] [-Object<String>] [-ObjectMatchProperty <String>] [-NestedMembership <SwitchParameter>] [-MembersOnly <SwitchParameter>] [-GroupsMatch <String>] [-MemberTypes <String[]>] [-GroupTypes <String>] [-Tenant<String>] [-TenantMatchProperty <String>] [-UserTypes <String>] [-DRARestServer <String>] [-DRARestPort <Int32>] [-IgnoreCertificateErrors <SwitchParameter>] [-Force <SwitchParameter>] [-Timeout <Int32>] [<CommonParameters>]
The New-DRAAzureGroupRule cmdlet creates the requested rule for Azure groups in the specified ActiveView. You must have the appropriate powers, such as those included in the Manage Security Model role to run this cmdlet.
Attribute / Description |
Parameters / Values |
||||
---|---|---|---|---|---|
Required |
Position |
Default Value |
Accept Pipeline input? |
Accept wildcard characters? |
|
ActiveView <String> Name of the ActiveView to add the rule to. |
true |
named |
true (ByPropertyName) |
false |
|
Name <String> Name of the ActiveView rule to be created. |
true |
named |
true (ByPropertyName) |
false |
|
Exclude [<SwitchParameter>] Specifies whether the ActiveView rule includes or excludes objects. By default, objects are included in the ActiveView rule. |
false |
named |
true (ByPropertyName) |
false |
|
RestrictUsageOnlyAllow [<SwitchParameter>] Enables the objects included in the ActiveView rule to be cloned, moved, or added to other groups. If the value for the RestrictUsageOnlyAllow parameter is true, the cmdlet ignores the value that is specified for the RestrictUsageDoNotAllow parameter. The default value is false. |
false |
named |
true (ByPropertyName) |
false |
|
RestrictUsageDoNotOnlyAllow [<SwitchParameter>] Restricts the objects included in the ActiveView rule from being cloned, moved, or added to groups. The default value is false. |
false |
named |
true (ByPropertyName) |
false |
|
Comment [<String>] Specifies additional information about the ActiveView rule. |
false |
named |
true (ByPropertyName) |
false |
|
Object [<String>] The objects to be included in the ActiveView rule. By default, all objects are included in the ActiveView rule. |
false |
named |
true (ByPropertyName) |
false |
|
ObjectMatchProperty [<String>] The object property to use when searching for objects. The value can be McsNameValue or McsPath. |
false |
named |
true (ByPropertyName) |
false |
|
NestedMembership [<SwitchParameter>] Specifies whether to include nested groups when searching for objects. By default, nested groups are included. |
false |
named |
true (ByPropertyName) |
false |
|
MembersOnly [<SwitchParameter>] Specifies whether to include only member objects from the matching groups or include both member objects and groups. By default, both groups and member objects are included. |
false |
named |
|
true (ByPropertyName) |
false |
AzureGroupsMatch [<String>] The Azure group to include when searching for objects. You can specify the exact Azure group name or a wildcard value. |
false |
named |
true (ByPropertyName) |
false |
|
MemberTypes [<String []>] The type of member object that is managed by the rule. This parameter can have the following values:
You can specify more than one value separated by a comma. If you specify NONE, the rule includes only groups. By default, the rule includes all member objects. |
|
|
|
|
|
GroupTypes [<String>] The type of group that is managed by the rule. This parameter can have the following values:
|
false |
named |
|
true (ByPropertyName) |
false |
Tenant [<String>] The name of the tenant. You can specify the exact name or a wildcard value. |
false |
named |
true (ByPropertyName) |
false |
|
TenantMatchProperty [<String>] The tenant property to use when searching for objects. The value can be McsFriendlyName. |
false |
named |
true (ByPropertyName) |
false |
|
UserTypes [<String>] The type of Azure user that is managed by the rule. This parameter can have the following values:
The default value is All. Specify 'All' to manage both member and guest users. |
false |
named |
true (ByPropertyName) |
false |
|
DRARestServer [<String>] The name of the computer running the DRA REST Service. The requested DRA operation will execute on this server. If the parameter is not specified, the value defaults to 'localhost'. |
false |
named |
|
true (ByPropertyName) |
false |
DRARestPort [<Int32>] The port number of the DRA REST Service. This parameter is only used when the DRARestServer parameter is also specified. If the parameter is not specified, the value defaults to 8755. |
false |
named |
8755 |
true (ByPropertyName) |
false |
IgnoreCertificateErrors [<SwitchParameter>] Allows the request to bypass any SSL certificate errors, such as the InvalidOperation error that occurs when the REST Service is bound to a self-signed certificate. |
false |
named |
|
false |
false |
Force [<SwitchParameter>] Suppresses any request for user input and supplies a 'yes' response. For example: -Force with a delete request will perform the delete without presenting the confirmation request to the user. |
false |
named |
|
false |
false |
Timeout [<Int32>] The number of seconds to wait before the request to the DRA REST server times out. To specify an infinite timeout, you can set this parameter to -1. |
false |
named |
100 seconds |
true (ByPropertyName) |
false |
<CommonParameters> Verbose, Debug, ErrorAction, ErrorVariable, WarningAction, WarningVariable, OutBuffer, PipelineVariable, and OutVariable. For more information, see About CommonParameters. |
|
|
|
|
|
NOTE:For more information, type "Get-Help New-DRAAzureGroupRule -detailed". For technical information, type "Get-Help New-DRAAzureGroupRule -full".
Example 10-13 1
PS C:\>New-DRAAzureGroupRule -Name "DRA Azure Group Rule" -ActiveView "My AV" -Object "*" -Tenant "NetIQ" -TenantMatchProperty "mcspath"
This example creates an Azure group rule named "DRA Azure Group Rule" under an existing ActiveView "My AV" with a list of Azure groups from the Azure tenant “NetIQ”.
Example 10-14 2
PS C:\>New-DRAAzureGroupRule -Name "DRA Azure Group Rule" -ActiveView "My AV" -Object "cn=e760e56b-3829-d745-aa93-c3c0d8d12fb5/az=fd74da8a-3212-4626-8f12-aca06dc133f6" -ObjectMatchProperty "mcspath"
This example creates an Azure group rule named "DRA Azure Group Rule" under an existing ActiveView "My AV" with the Azure group that is specified in the identifier “cn=e760e56b-3829-d745-aa93-c3c0d8d12fb5/az=fd74da8a-3212-4626-8f12-aca06dc133f6”.