10.11 New-DRAAzureTenantRule

Synopsis

Creates a rule for Azure tenants in the specified ActiveView.

Syntax

New-DRAAzureTenantRule -ActiveView <String> -Name <String> [-Exclude <SwitchParameter>] [-RestrictUsageOnlyAllow <SwitchParameter>] [-RestrictUsageDoNotAllow <SwitchParameter>] [-Comment <String>] 
[-ObjectTypes <String[]>] [-ObjectsOnly <String>] [-Tenant <String>] [-TenantMatchProperty <String>] [-UserTypes <String>] [-DRARestServer <String>] [-DRARestPort <Int32>] [-IgnoreCertificateErrors <SwitchParameter>] [-Force <SwitchParameter>] [-Timeout <Int32>] [<CommonParameters>]

Description

The New-DRAAzureTenantRule cmdlet creates the requested rule for Azure tenants in the specified ActiveView. You must have the appropriate powers, such as those included in the Manage Security Model role to run this cmdlet.

Parameters

Attribute / Description

Parameters / Values

Required

Position

Default Value

Accept Pipeline input?

Accept wildcard characters?

ActiveView <String>

Name of the ActiveView to add the rule to.

true

named

true (ByPropertyName)

false

Name <String>

Name of the ActiveView rule to be created.

true

named

true (ByPropertyName)

false

Exclude [<SwitchParameter>]

Specifies whether the ActiveView rule includes or excludes objects. By default, objects are included in the ActiveView rule.

false

named

true (ByPropertyName)

false

RestrictUsageOnlyAllow [<SwitchParameter>]

Enables the objects included in the ActiveView rule to be cloned, moved, or added to other groups. If the value for the RestrictUsageOnlyAllow parameter is true, the cmdlet ignores the value that is specified for the RestrictUsageDoNotAllow parameter. The default value is false.

false

named

true (ByPropertyName)

false

RestrictUsageDoNotOnlyAllow [<SwitchParameter>]

Restricts the objects included in the ActiveView rule from being cloned, moved, or added to groups. The default value is false.

false

named

true (ByPropertyName)

false

Comment [<String>]

Specifies additional information about the ActiveView rule.

false

named

true (ByPropertyName)

false

ObjectTypes [<String[]>]

The type of object that is managed by the rule. This parameter can have the following values:

  • AU or AzureUser

  • AG or AzureGroup

  • All

  • None

You can specify more than one value separated by a comma. If you specify NONE, only tenants are included. By default, the rule includes all types of objects.

false

named

true (ByPropertyName)

false

ObjectsOnly [<String>]

Specifies whether to include only the matching objects or include both matching objects and tenants. By default, the rule includes both objects and tenants.

false

named

true (ByPropertyName)

false

Tenant [<String>]

The name of the tenant to use when searching for objects. You can specify the exact tenant name or a wildcard value.

false

named

true (ByPropertyName)

false

TenantMatchProperty [<String>]

The tenant property to use when searching for objects. The value can be McsFriendlyName or McsPath.

false

named

true (ByPropertyName)

false

UserTypes [<String>]

The type of Azure user that is managed by the rule. This parameter can have the following values:

  1. M or Member

  2. G or Guest

  3. All

The default value is All. Specify 'All' to manage both member and guest users.

false

named

true (ByPropertyName)

false

DRARestServer [<String>]

The name of the computer running the DRA REST Service. The requested DRA operation will execute on this server. If the parameter is not specified, the value defaults to 'localhost'.

false

named

 

true (ByPropertyName)

false

DRARestPort [<Int32>]

The port number of the DRA REST Service. This parameter is only used when the DRARestServer parameter is also specified. If the parameter is not specified, the value defaults to 8755.

false

named

8755

true (ByPropertyName)

false

IgnoreCertificateErrors [<SwitchParameter>]

Allows the request to bypass any SSL certificate errors, such as the InvalidOperation error that occurs when the REST Service is bound to a self-signed certificate.

false

named

 

false

false

Force [<SwitchParameter>]

Suppresses any request for user input and supplies a 'yes' response. For example: -Force with a delete request will perform the delete without presenting the confirmation request to the user.

false

named

 

false

false

Timeout [<Int32>]

The number of seconds to wait before the request to the DRA REST server times out. To specify an infinite timeout, you can set this parameter to -1.

false

named

100 seconds

true (ByPropertyName)

false

<CommonParameters>

Verbose, Debug, ErrorAction, ErrorVariable, WarningAction, WarningVariable, OutBuffer, PipelineVariable, and OutVariable. For more information, see About CommonParameters.

 

 

 

 

 

NOTE:For more information, type "Get-Help New-DRAAzureTenantRule -detailed". For technical information, type "Get-Help New-DRAAzureTenantRule -full".

Example 10-15 1

PS C:\>New-DraAzureTenantRule -Name "DRA Azure Tenant Rule" -ActiveView "My AV" -Tenant "NetIQ"

This example creates an Azure tenant rule named "DRA Azure Tenant Rule" under an existing ActiveView "My AV" with a list of users and groups in the Azure tenant “NetIQ”.