Skip to content

Describe Application Assignment

ssoadmin_describe_application_assignment R Documentation

Retrieves a direct assignment of a user or group to an application

Description

Retrieves a direct assignment of a user or group to an application. If the user doesn’t have a direct assignment to the application, the user may still have access to the application through a group. Therefore, don’t use this API to test access to an application for a user. Instead use list_application_assignments_for_principal.

Usage

ssoadmin_describe_application_assignment(ApplicationArn, PrincipalId,
  PrincipalType)

Arguments

ApplicationArn

[required] Specifies the ARN of the application. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces in the Amazon Web Services General Reference.

PrincipalId

[required] An identifier for an object in IAM Identity Center, such as a user or group. PrincipalIds are GUIDs (For example, f81d4fae-7dec-11d0-a765-00a0c91e6bf6). For more information about PrincipalIds in IAM Identity Center, see the IAM Identity Center Identity Store API Reference.

PrincipalType

[required] The entity type for which the assignment will be created.

Value

A list with the following syntax:

list(
  ApplicationArn = "string",
  PrincipalId = "string",
  PrincipalType = "USER"|"GROUP"
)

Request syntax

svc$describe_application_assignment(
  ApplicationArn = "string",
  PrincipalId = "string",
  PrincipalType = "USER"|"GROUP"
)