DeleteAccessAssignment
Calls DeleteAccessAssignment to remove an access assignment from an account in a resource directory.
Operation description
This API operation is an asynchronous operation. You can use the TaskId in the response parameters to invoke GetTask to query the task execute status.
This topic provides an example on how to remove the authorization on the account in a resource directory 114240524784****, where the CloudSSO user u-00q8wbq42wiltcrk**** uses the access configuration ac-00jhtfl8thteu6uj****.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cloudsso:DeleteAccessAssignment |
delete |
*AccessConfiguration
User
Group
*Account
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| DirectoryId |
string |
Yes |
The directory ID. |
d-00fc2p61**** |
| AccessConfigurationId |
string |
Yes |
The access configuration ID. |
ac-00jhtfl8thteu6uj**** |
| TargetType |
string |
Yes |
The type of the task target. Valid values: RD-Account, which indicates that the task target type is an account in a resource directory. |
RD-Account |
| TargetId |
string |
Yes |
The ID of the task target. |
114240524784**** |
| PrincipalType |
string |
Yes |
The type of the CloudSSO identity. Valid values:
|
User |
| PrincipalId |
string |
Yes |
The ID of the CloudSSO identity. The value depends on the PrincipalType:
|
u-00q8wbq42wiltcrk**** |
| DeprovisionStrategy |
string |
No |
Specifies whether to remove the access configuration deployment when you remove the last authorization on an account in a resource directory that uses the access configuration. Valid values:
|
None |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| Task |
object |
The task information. |
|
| Status |
string |
The task status. Valid values:
|
InProgress |
| TaskId |
string |
The task ID. |
t-shfqw1u1edszvxw5**** |
| PrincipalId |
string |
The ID of the CloudSSO identity. |
u-00q8wbq42wiltcrk**** |
| TargetPath |
string |
The path ID of the task target in the resource directory. |
rd-3G****/r-Wm****/114240524784**** |
| PrincipalName |
string |
The name of the CloudSSO identity. |
Alice |
| TargetName |
string |
The name of the task target. |
dev-test |
| TargetId |
string |
The ID of the task target. |
114240524784**** |
| AccessConfigurationName |
string |
The name of the access configuration. |
ECS-Admin |
| TargetPathName |
string |
The path name of the task target in the resource directory. |
rd-3G****/root/dev-test |
| TaskType |
string |
The type of the task. Valid values: DeleteAccessAssignment, which indicates a task to remove an access assignment from an account in a resource directory. |
DeleteAccessAssignment |
| TargetType |
string |
The type of the task target. Valid values: RD-Account, which indicates that the task target type is an account in a resource directory. |
RD-Account |
| AccessConfigurationId |
string |
The access configuration ID. |
ac-00jhtfl8thteu6uj**** |
| PrincipalType |
string |
The type of the CloudSSO identity. Valid values:
|
User |
| OriginTargetId |
string |
114240524784**** |
|
| RequestId |
string |
The request ID. |
5C9D0CF4-5CE8-5CE6-932A-826EF4ADD007 |
Examples
Success response
JSON format
{
"Task": {
"Status": "InProgress",
"TaskId": "t-shfqw1u1edszvxw5****",
"PrincipalId": "u-00q8wbq42wiltcrk****",
"TargetPath": "rd-3G****/r-Wm****/114240524784****",
"PrincipalName": "Alice",
"TargetName": "dev-test",
"TargetId": "114240524784****",
"AccessConfigurationName": "ECS-Admin",
"TargetPathName": "rd-3G****/root/dev-test",
"TaskType": "DeleteAccessAssignment",
"TargetType": "RD-Account",
"AccessConfigurationId": "ac-00jhtfl8thteu6uj****",
"PrincipalType": "User",
"OriginTargetId": "114240524784****"
},
"RequestId": "5C9D0CF4-5CE8-5CE6-932A-826EF4ADD007"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.