Skip to main content

Retrieve unapplied group policy objects for all SVMs

Contributors

GET /protocols/cifs/group-policies

Introduced In: 9.12

Retrieves group policy objects that are yet to be applied for all SVMs.

  • vserver cifs group-policy show-defined

Parameters

Name Type In Required Description

link

string

query

False

Filter by link

security_settings.registry_values.signing_required

boolean

query

False

Filter by security_settings.registry_values.signing_required

security_settings.event_audit_settings.object_access_type

string

query

False

Filter by security_settings.event_audit_settings.object_access_type

security_settings.event_audit_settings.logon_type

string

query

False

Filter by security_settings.event_audit_settings.logon_type

security_settings.restricted_groups

string

query

False

Filter by security_settings.restricted_groups

security_settings.kerberos.max_clock_skew

string

query

False

Filter by security_settings.kerberos.max_clock_skew

security_settings.kerberos.max_ticket_age

string

query

False

Filter by security_settings.kerberos.max_ticket_age

security_settings.kerberos.max_renew_age

string

query

False

Filter by security_settings.kerberos.max_renew_age

security_settings.restrict_anonymous.no_enumeration_of_sam_accounts_and_shares

boolean

query

False

Filter by security_settings.restrict_anonymous.no_enumeration_of_sam_accounts_and_shares

security_settings.restrict_anonymous.anonymous_access_to_shares_and_named_pipes_restricted

boolean

query

False

Filter by security_settings.restrict_anonymous.anonymous_access_to_shares_and_named_pipes_restricted

security_settings.restrict_anonymous.no_enumeration_of_sam_accounts

boolean

query

False

Filter by security_settings.restrict_anonymous.no_enumeration_of_sam_accounts

security_settings.restrict_anonymous.combined_restriction_for_anonymous_user

string

query

False

Filter by security_settings.restrict_anonymous.combined_restriction_for_anonymous_user

security_settings.privilege_rights.take_ownership_users

string

query

False

Filter by security_settings.privilege_rights.take_ownership_users

security_settings.privilege_rights.change_notify_users

string

query

False

Filter by security_settings.privilege_rights.change_notify_users

security_settings.privilege_rights.security_privilege_users

string

query

False

Filter by security_settings.privilege_rights.security_privilege_users

security_settings.event_log_settings.max_size

integer

query

False

Filter by security_settings.event_log_settings.max_size

security_settings.event_log_settings.retention_method

string

query

False

Filter by security_settings.event_log_settings.retention_method

security_settings.files_or_folders

string

query

False

Filter by security_settings.files_or_folders

uuid

string

query

False

Filter by uuid

svm.uuid

string

query

False

Filter by svm.uuid

svm.name

string

query

False

Filter by svm.name

central_access_policy_settings

string

query

False

Filter by central_access_policy_settings

central_access_policy_staging_audit_type

string

query

False

Filter by central_access_policy_staging_audit_type

name

string

query

False

Filter by name

  • minLength: 1

extensions

string

query

False

Filter by extensions

file_system_path

string

query

False

Filter by file_system_path

ldap_path

string

query

False

Filter by ldap_path

enabled

boolean

query

False

Filter by enabled

index

integer

query

False

Filter by index

version

integer

query

False

Filter by version

registry_settings.refresh_time_interval

string

query

False

Filter by registry_settings.refresh_time_interval

registry_settings.branchcache.supported_hash_version

string

query

False

Filter by registry_settings.branchcache.supported_hash_version

registry_settings.branchcache.hash_publication_mode

string

query

False

Filter by registry_settings.branchcache.hash_publication_mode

registry_settings.refresh_time_random_offset

string

query

False

Filter by registry_settings.refresh_time_random_offset

fields

array[string]

query

False

Specify the fields to return.

return_records

boolean

query

False

The default is true for GET calls. When set to false, only the number of records is returned.

  • Default value: 1

return_timeout

integer

query

False

The number of seconds to allow the call to execute before returning. When iterating over a collection, the default is 15 seconds. ONTAP returns earlier if either max records or the end of the collection is reached.

  • Default value: 1

  • Max value: 120

  • Min value: 0

max_records

integer

query

False

Limit the number of records returned.

order_by

array[string]

query

False

Order results by specified fields and optional [asc

Response

Status: 200, Ok
Name Type Description

_links

_links

num_records

integer

Number of central access rules.

records

array[policies_and_rules_to_be_applied]

Example response
{
  "_links": {
    "next": {
      "href": "/api/resourcelink"
    },
    "self": {
      "href": "/api/resourcelink"
    }
  },
  "num_records": 1,
  "records": [
    {
      "svm": {
        "_links": {
          "self": {
            "href": "/api/resourcelink"
          }
        },
        "name": "svm1",
        "uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
      },
      "to_be_applied": {
        "access_policies": [
          {
            "create_time": "2018-01-01 11:00:00 -0500",
            "description": "policy #1",
            "member_rules": [
              "r1",
              "r2"
            ],
            "name": "p1",
            "sid": "S-1-5-21-256008430-3394229847-3930036330-1001",
            "svm": {
              "_links": {
                "self": {
                  "href": "/api/resourcelink"
                }
              },
              "name": "svm1",
              "uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
            },
            "update_time": "2018-01-01 11:00:00 -0500"
          }
        ],
        "access_rules": [
          {
            "create_time": "2018-01-01 11:00:00 -0500",
            "current_permission": "O:SYG:SYD:AR(A;;FA;;;WD)",
            "description": "rule #1",
            "name": "p1",
            "proposed_permission": "O:SYG:SYD:(A;;FA;;;OW)(A;;FA;;;BA)(A;;FA;;;SY)",
            "resource_criteria": "department",
            "svm": {
              "_links": {
                "self": {
                  "href": "/api/resourcelink"
                }
              },
              "name": "svm1",
              "uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
            },
            "update_time": "2018-01-01 11:00:00 -0500"
          }
        ],
        "objects": [
          {
            "central_access_policy_settings": [
              "p1",
              "p2"
            ],
            "central_access_policy_staging_audit_type": "none",
            "extensions": [
              "audit",
              "security"
            ],
            "file_system_path": "\\test.com\\SysVol\\test.com\\policies\\{42474212-3f9d-4489-ae01-6fcf4f805d4c}",
            "index": 1,
            "ldap_path": "cn={42474212-3f9d-4489-ae01-6fcf4f805d4c},cn=policies,cn=system,DC=TEST,DC=COM",
            "link": "domain",
            "name": "test_policy",
            "registry_settings": {
              "branchcache": {
                "hash_publication_mode": "disabled",
                "supported_hash_version": "version1"
              },
              "refresh_time_interval": "P15M",
              "refresh_time_random_offset": "P1D"
            },
            "security_settings": {
              "event_audit_settings": {
                "logon_type": "failure",
                "object_access_type": "failure"
              },
              "event_log_settings": {
                "max_size": 2048,
                "retention_method": "do_not_overwrite"
              },
              "files_or_folders": [
                "/vol1/home",
                "/vol1/dir1"
              ],
              "kerberos": {
                "max_clock_skew": "P15M",
                "max_renew_age": "P2D",
                "max_ticket_age": "P24H"
              },
              "privilege_rights": {
                "change_notify_users": [
                  "usr1",
                  "usr2"
                ],
                "security_privilege_users": [
                  "usr1",
                  "usr2"
                ],
                "take_ownership_users": [
                  "usr1",
                  "usr2"
                ]
              },
              "restrict_anonymous": {
                "combined_restriction_for_anonymous_user": "no_access"
              },
              "restricted_groups": [
                "test_grp1",
                "test_grp2"
              ]
            },
            "svm": {
              "_links": {
                "self": {
                  "href": "/api/resourcelink"
                }
              },
              "name": "svm1",
              "uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
            },
            "uuid": "42474212-3f9d-4489-ae01-6fcf4f805d4c",
            "version": 7
          }
        ],
        "restricted_groups": [
          {
            "group_name": "test_group",
            "link": "domain",
            "members": [
              "DOMAIN/test_user",
              "DOMAIN/user2"
            ],
            "memberships": [
              "DOMAIN/AdministratorGrp",
              "DOMAIN/deptMark"
            ],
            "policy_name": "test_policy",
            "svm": {
              "_links": {
                "self": {
                  "href": "/api/resourcelink"
                }
              },
              "name": "svm1",
              "uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
            },
            "version": 7
          }
        ]
      }
    }
  ]
}

Error

Status: Default, Error
Name Type Description

error

returned_error

Example error
{
  "error": {
    "arguments": [
      {
        "code": "string",
        "message": "string"
      }
    ],
    "code": "4",
    "message": "entry doesn't exist",
    "target": "uuid"
  }
}

Definitions

See Definitions

href

Name Type Description

href

string

Name Type Description

next

href

self