SCDeviceConditionalAccessPolicy¶
Parameters¶
| Parameter | Attribute | DataType | Description | Allowed Values |
|---|---|---|---|---|
| Name | Key | String | The name of the Device Conditional Access Policy. | |
| Ensure | Write | String | Specify if this policy should exist or not. | Present, Absent |
| Comment | Write | String | The Comment parameter specifies an optional comment. | |
| Enabled | Write | Boolean | The Enabled parameter specifies whether the policy is enabled. | |
| Credential | Write | PSCredential | Credentials of Security and Compliance Center Admin | |
| ApplicationId | Write | String | Id of the Azure Active Directory application to authenticate with. | |
| TenantId | Write | String | Id of the Azure Active Directory tenant used for authentication. | |
| CertificateThumbprint | Write | String | Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication. | |
| CertificatePassword | Write | PSCredential | Username can be made up to anything but password will be used for CertificatePassword | |
| CertificatePath | Write | String | Path to certificate used in service principal usually a PFX file. | |
| ManagedIdentity | Write | Boolean | Managed ID being used for authentication. | |
| AccessTokens | Write | StringArray[] | Access token used for authentication. |
Description¶
This resource configures a Device Conditional Access Policy in Purview.
Permissions¶
Purview¶
To authenticate with Microsoft Purview, this resource requires the following permissions:
Roles¶
- Read
- View-Only Device Management
- Update
- Device Management
Role Groups¶
- Read
- Security Reader
- Update
- Compliance Data Administrator
Office 365 Exchange Online¶
To authenticate with the Office 365 Exchange Online API, this resource requires the following permissions:
Delegated permissions¶
- Read
-
None
-
Update
- None
Application permissions¶
- Read
-
Exchange.ManageAsApp
-
Update
- Exchange.ManageAsApp
Examples¶
Example 1¶
This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.
Configuration Example
{
param
(
[Parameter(Mandatory = $true)]
[PSCredential]
$Credscredential
)
Import-DscResource -ModuleName Microsoft365DSC
node localhost
{
SCDeviceConditionalAccessPolicy 'ConfigureDeviceConditionalAccessPolicy'
{
Name = "Human Resources"
Comment = "Device Conditional Access Policy for Human Resources department"
Enabled = $True
Ensure = "Present"
Credential = $Credscredential
}
}
}