Cisco ISE v0.2.2 published on Friday, Apr 25, 2025 by Pulumi
ise.deviceadmin.getAuthorizationExceptionRule
Explore with Pulumi AI
This data source can read the Device Admin Authorization Exception Rule.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as ise from "@pulumi/ise";
const example = ise.deviceadmin.getAuthorizationExceptionRule({
    id: "76d24097-41c4-4558-a4d0-a8c07ac08470",
    policySetId: "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
});
import pulumi
import pulumi_ise as ise
example = ise.deviceadmin.get_authorization_exception_rule(id="76d24097-41c4-4558-a4d0-a8c07ac08470",
    policy_set_id="d82952cb-b901-4b09-b363-5ebf39bdbaf9")
package main
import (
	"github.com/pulumi/pulumi-ise/sdk/go/ise/deviceadmin"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		_, err := deviceadmin.LookupAuthorizationExceptionRule(ctx, &deviceadmin.LookupAuthorizationExceptionRuleArgs{
			Id:          pulumi.StringRef("76d24097-41c4-4558-a4d0-a8c07ac08470"),
			PolicySetId: "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
		}, nil)
		if err != nil {
			return err
		}
		return nil
	})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Ise = Pulumi.Ise;
return await Deployment.RunAsync(() => 
{
    var example = Ise.DeviceAdmin.GetAuthorizationExceptionRule.Invoke(new()
    {
        Id = "76d24097-41c4-4558-a4d0-a8c07ac08470",
        PolicySetId = "d82952cb-b901-4b09-b363-5ebf39bdbaf9",
    });
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.ise.deviceadmin.DeviceadminFunctions;
import com.pulumi.ise.deviceadmin.inputs.GetAuthorizationExceptionRuleArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }
    public static void stack(Context ctx) {
        final var example = DeviceadminFunctions.getAuthorizationExceptionRule(GetAuthorizationExceptionRuleArgs.builder()
            .id("76d24097-41c4-4558-a4d0-a8c07ac08470")
            .policySetId("d82952cb-b901-4b09-b363-5ebf39bdbaf9")
            .build());
    }
}
variables:
  example:
    fn::invoke:
      function: ise:deviceadmin:getAuthorizationExceptionRule
      arguments:
        id: 76d24097-41c4-4558-a4d0-a8c07ac08470
        policySetId: d82952cb-b901-4b09-b363-5ebf39bdbaf9
Using getAuthorizationExceptionRule
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getAuthorizationExceptionRule(args: GetAuthorizationExceptionRuleArgs, opts?: InvokeOptions): Promise<GetAuthorizationExceptionRuleResult>
function getAuthorizationExceptionRuleOutput(args: GetAuthorizationExceptionRuleOutputArgs, opts?: InvokeOptions): Output<GetAuthorizationExceptionRuleResult>def get_authorization_exception_rule(id: Optional[str] = None,
                                     name: Optional[str] = None,
                                     policy_set_id: Optional[str] = None,
                                     opts: Optional[InvokeOptions] = None) -> GetAuthorizationExceptionRuleResult
def get_authorization_exception_rule_output(id: Optional[pulumi.Input[str]] = None,
                                     name: Optional[pulumi.Input[str]] = None,
                                     policy_set_id: Optional[pulumi.Input[str]] = None,
                                     opts: Optional[InvokeOptions] = None) -> Output[GetAuthorizationExceptionRuleResult]func LookupAuthorizationExceptionRule(ctx *Context, args *LookupAuthorizationExceptionRuleArgs, opts ...InvokeOption) (*LookupAuthorizationExceptionRuleResult, error)
func LookupAuthorizationExceptionRuleOutput(ctx *Context, args *LookupAuthorizationExceptionRuleOutputArgs, opts ...InvokeOption) LookupAuthorizationExceptionRuleResultOutput> Note: This function is named LookupAuthorizationExceptionRule in the Go SDK.
public static class GetAuthorizationExceptionRule 
{
    public static Task<GetAuthorizationExceptionRuleResult> InvokeAsync(GetAuthorizationExceptionRuleArgs args, InvokeOptions? opts = null)
    public static Output<GetAuthorizationExceptionRuleResult> Invoke(GetAuthorizationExceptionRuleInvokeArgs args, InvokeOptions? opts = null)
}public static CompletableFuture<GetAuthorizationExceptionRuleResult> getAuthorizationExceptionRule(GetAuthorizationExceptionRuleArgs args, InvokeOptions options)
public static Output<GetAuthorizationExceptionRuleResult> getAuthorizationExceptionRule(GetAuthorizationExceptionRuleArgs args, InvokeOptions options)
fn::invoke:
  function: ise:deviceadmin/getAuthorizationExceptionRule:getAuthorizationExceptionRule
  arguments:
    # arguments dictionaryThe following arguments are supported:
- PolicySet stringId 
- Policy set ID
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- PolicySet stringId 
- Policy set ID
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet stringId 
- Policy set ID
- id string
- The id of the object
- name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policy_set_ strid 
- Policy set ID
- id str
- The id of the object
- name str
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
getAuthorizationExceptionRule Result
The following output properties are available:
- Childrens
List<GetAuthorization Exception Rule Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- CommandSets List<string>
- Command sets enforce the specified list of commands that can be executed by a device administrator
- ConditionAttribute stringName 
- Dictionary attribute name
- ConditionAttribute stringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionDictionary stringName 
- Dictionary name
- ConditionDictionary stringValue 
- Dictionary value
- ConditionId string
- UUID for condition
- ConditionIs boolNegate 
- Indicates whereas this condition is in negate mode
- ConditionOperator string
- Equality operator
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- Default bool
- Indicates if this rule is the default one
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- PolicySet stringId 
- Policy set ID
- Profile string
- Device admin profiles control the initial login session of the device administrator
- Rank int
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- State string
- The state that the rule is in. A disabled rule cannot be matched.
- Childrens
[]GetAuthorization Exception Rule Children 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- CommandSets []string
- Command sets enforce the specified list of commands that can be executed by a device administrator
- ConditionAttribute stringName 
- Dictionary attribute name
- ConditionAttribute stringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionDictionary stringName 
- Dictionary name
- ConditionDictionary stringValue 
- Dictionary value
- ConditionId string
- UUID for condition
- ConditionIs boolNegate 
- Indicates whereas this condition is in negate mode
- ConditionOperator string
- Equality operator
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- Default bool
- Indicates if this rule is the default one
- Id string
- The id of the object
- Name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- PolicySet stringId 
- Policy set ID
- Profile string
- Device admin profiles control the initial login session of the device administrator
- Rank int
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- State string
- The state that the rule is in. A disabled rule cannot be matched.
- childrens
List<GetAuthorization Exception Rule Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- commandSets List<String>
- Command sets enforce the specified list of commands that can be executed by a device administrator
- conditionAttribute StringName 
- Dictionary attribute name
- conditionAttribute StringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- conditionDictionary StringName 
- Dictionary name
- conditionDictionary StringValue 
- Dictionary value
- conditionId String
- UUID for condition
- conditionIs BooleanNegate 
- Indicates whereas this condition is in negate mode
- conditionOperator String
- Equality operator
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default_ Boolean
- Indicates if this rule is the default one
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- profile String
- Device admin profiles control the initial login session of the device administrator
- rank Integer
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state String
- The state that the rule is in. A disabled rule cannot be matched.
- childrens
GetAuthorization Exception Rule Children[] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- commandSets string[]
- Command sets enforce the specified list of commands that can be executed by a device administrator
- conditionAttribute stringName 
- Dictionary attribute name
- conditionAttribute stringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- conditionDictionary stringName 
- Dictionary name
- conditionDictionary stringValue 
- Dictionary value
- conditionId string
- UUID for condition
- conditionIs booleanNegate 
- Indicates whereas this condition is in negate mode
- conditionOperator string
- Equality operator
- conditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default boolean
- Indicates if this rule is the default one
- id string
- The id of the object
- name string
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet stringId 
- Policy set ID
- profile string
- Device admin profiles control the initial login session of the device administrator
- rank number
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state string
- The state that the rule is in. A disabled rule cannot be matched.
- childrens
Sequence[GetAuthorization Exception Rule Children] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- command_sets Sequence[str]
- Command sets enforce the specified list of commands that can be executed by a device administrator
- condition_attribute_ strname 
- Dictionary attribute name
- condition_attribute_ strvalue 
- Attribute value for condition. Value type is specified in dictionary object.
- condition_dictionary_ strname 
- Dictionary name
- condition_dictionary_ strvalue 
- Dictionary value
- condition_id str
- UUID for condition
- condition_is_ boolnegate 
- Indicates whereas this condition is in negate mode
- condition_operator str
- Equality operator
- condition_type str
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default bool
- Indicates if this rule is the default one
- id str
- The id of the object
- name str
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policy_set_ strid 
- Policy set ID
- profile str
- Device admin profiles control the initial login session of the device administrator
- rank int
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state str
- The state that the rule is in. A disabled rule cannot be matched.
- childrens List<Property Map>
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- commandSets List<String>
- Command sets enforce the specified list of commands that can be executed by a device administrator
- conditionAttribute StringName 
- Dictionary attribute name
- conditionAttribute StringValue 
- Attribute value for condition. Value type is specified in dictionary object.
- conditionDictionary StringName 
- Dictionary name
- conditionDictionary StringValue 
- Dictionary value
- conditionId String
- UUID for condition
- conditionIs BooleanNegate 
- Indicates whereas this condition is in negate mode
- conditionOperator String
- Equality operator
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- default Boolean
- Indicates if this rule is the default one
- id String
- The id of the object
- name String
- Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses]
- policySet StringId 
- Policy set ID
- profile String
- Device admin profiles control the initial login session of the device administrator
- rank Number
- The rank (priority) in relation to other rules. Lower rank is higher priority.
- state String
- The state that the rule is in. A disabled rule cannot be matched.
Supporting Types
GetAuthorizationExceptionRuleChildren    
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- Childrens
List<GetAuthorization Exception Rule Children Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- Childrens
[]GetAuthorization Exception Rule Children Children 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- ConditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- childrens
List<GetAuthorization Exception Rule Children Children> 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
- attributeName string
- Dictionary attribute name
- attributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- childrens
GetAuthorization Exception Rule Children Children[] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- conditionType string
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionaryName string
- Dictionary name
- dictionaryValue string
- Dictionary value
- id string
- UUID for condition
- isNegate boolean
- Indicates whereas this condition is in negate mode
- operator string
- Equality operator
- attribute_name str
- Dictionary attribute name
- attribute_value str
- Attribute value for condition. Value type is specified in dictionary object.
- childrens
Sequence[GetAuthorization Exception Rule Children Children] 
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- condition_type str
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionary_name str
- Dictionary name
- dictionary_value str
- Dictionary value
- id str
- UUID for condition
- is_negate bool
- Indicates whereas this condition is in negate mode
- operator str
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- childrens List<Property Map>
- List of child conditions. condition_typemust be one ofConditionAndBlockorConditionOrBlock.
- conditionType String
- Indicates whether the record is the condition itself or a logical aggregation. Logical aggreation indicates that additional conditions are present under the children attribute.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
GetAuthorizationExceptionRuleChildrenChildren     
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionType string
- Condition type.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- AttributeName string
- Dictionary attribute name
- AttributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- ConditionType string
- Condition type.
- DictionaryName string
- Dictionary name
- DictionaryValue string
- Dictionary value
- Id string
- UUID for condition
- IsNegate bool
- Indicates whereas this condition is in negate mode
- Operator string
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- conditionType String
- Condition type.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
- attributeName string
- Dictionary attribute name
- attributeValue string
- Attribute value for condition. Value type is specified in dictionary object.
- conditionType string
- Condition type.
- dictionaryName string
- Dictionary name
- dictionaryValue string
- Dictionary value
- id string
- UUID for condition
- isNegate boolean
- Indicates whereas this condition is in negate mode
- operator string
- Equality operator
- attribute_name str
- Dictionary attribute name
- attribute_value str
- Attribute value for condition. Value type is specified in dictionary object.
- condition_type str
- Condition type.
- dictionary_name str
- Dictionary name
- dictionary_value str
- Dictionary value
- id str
- UUID for condition
- is_negate bool
- Indicates whereas this condition is in negate mode
- operator str
- Equality operator
- attributeName String
- Dictionary attribute name
- attributeValue String
- Attribute value for condition. Value type is specified in dictionary object.
- conditionType String
- Condition type.
- dictionaryName String
- Dictionary name
- dictionaryValue String
- Dictionary value
- id String
- UUID for condition
- isNegate Boolean
- Indicates whereas this condition is in negate mode
- operator String
- Equality operator
Package Details
- Repository
- ise pulumi/pulumi-ise
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the iseTerraform Provider.
