v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/auth-method-create-azure-ad

Request body

access-expiresinteger

Access expiration date in Unix timestamp (select 0 for access without expiry date)

allowed-client-typestring[]

limit the auth method usage for specific client types [cli,ui,gateway-admin,sdk,mobile,extension]

audiencestring

Deprecated (Deprecated) The audience in the JWT

audit-logs-claimsstring[]

Subclaims to include in audit logs, e.g "--audit-logs-claims email --audit-logs-claims username"

bound-group-idstring[]

A list of group ids that the access is restricted to

bound-ipsstring[]

A CIDR whitelist with the IPs that the access is restricted to

bound-providersstring[]

A list of resource providers that the access is restricted to (e.g, Microsoft.Compute, Microsoft.ManagedIdentity, etc)

bound-resource-idstring[]

A list of full resource ids that the access is restricted to

bound-resource-namesstring[]

A list of resource names that the access is restricted to (e.g, a virtual machine name, scale set name, etc).

bound-resource-typesstring[]

A list of resource types that the access is restricted to (e.g, virtualMachines, userAssignedIdentities, etc)

bound-rg-idstring[]

A list of resource groups that the access is restricted to

bound-spidstring[]

A list of service principal IDs that the access is restricted to

bound-sub-idstring[]

A list of subscription ids that the access is restricted to

bound-tenant-idstring required

The Azure tenant id that the access is restricted to

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Auth Method description

expiration-event-instring[]

How many days before the expiration of the auth method would you like to be notified.

force-sub-claimsboolean

if true: enforce role-association must include sub claims

gw-bound-ipsstring[]

A CIDR whitelist with the GW IPs that the access is restricted to

issuerstring

Issuer URL

jsonboolean

Set output format to JSON

jwks-uristring

The URL to the JSON Web Key Set (JWKS) that containing the public keys that should be used to verify any JSON Web Token (JWT) issued by the authorization server.

jwt-ttlinteger

Jwt TTL

namestring required

Auth Method name

product-typestring[]

Choose the relevant product type for the auth method [sm, sra, pm, dp, ca]

tokenstring

Authentication token (see /auth and /configure)

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

unique-identifierstring

A unique identifier (ID) value which is a "sub claim" name that contains details uniquely identifying that resource. This "sub claim" is used to distinguish between different identities.

Response

authMethodCreateAzureADResponse wraps response body.

access_idstring
access_keystring
namestring
prv_keystring