Retrieve unapplied group policy objects for all SVMs
GET /protocols/cifs/group-policies
Introduced In: 9.12
Retrieves group policy objects that are yet to be applied for all SVMs.
Related ONTAP commands
-
vserver cifs group-policy show-defined
Parameters
Name | Type | In | Required | Description |
---|---|---|---|---|
link |
string |
query |
False |
Filter by link |
security_settings.registry_values.signing_required |
boolean |
query |
False |
Filter by security_settings.registry_values.signing_required |
security_settings.event_audit_settings.object_access_type |
string |
query |
False |
Filter by security_settings.event_audit_settings.object_access_type |
security_settings.event_audit_settings.logon_type |
string |
query |
False |
Filter by security_settings.event_audit_settings.logon_type |
security_settings.restricted_groups |
string |
query |
False |
Filter by security_settings.restricted_groups |
security_settings.kerberos.max_clock_skew |
string |
query |
False |
Filter by security_settings.kerberos.max_clock_skew |
security_settings.kerberos.max_ticket_age |
string |
query |
False |
Filter by security_settings.kerberos.max_ticket_age |
security_settings.kerberos.max_renew_age |
string |
query |
False |
Filter by security_settings.kerberos.max_renew_age |
security_settings.restrict_anonymous.no_enumeration_of_sam_accounts_and_shares |
boolean |
query |
False |
Filter by security_settings.restrict_anonymous.no_enumeration_of_sam_accounts_and_shares |
security_settings.restrict_anonymous.anonymous_access_to_shares_and_named_pipes_restricted |
boolean |
query |
False |
Filter by security_settings.restrict_anonymous.anonymous_access_to_shares_and_named_pipes_restricted |
security_settings.restrict_anonymous.no_enumeration_of_sam_accounts |
boolean |
query |
False |
Filter by security_settings.restrict_anonymous.no_enumeration_of_sam_accounts |
security_settings.restrict_anonymous.combined_restriction_for_anonymous_user |
string |
query |
False |
Filter by security_settings.restrict_anonymous.combined_restriction_for_anonymous_user |
security_settings.privilege_rights.take_ownership_users |
string |
query |
False |
Filter by security_settings.privilege_rights.take_ownership_users |
security_settings.privilege_rights.change_notify_users |
string |
query |
False |
Filter by security_settings.privilege_rights.change_notify_users |
security_settings.privilege_rights.security_privilege_users |
string |
query |
False |
Filter by security_settings.privilege_rights.security_privilege_users |
security_settings.event_log_settings.max_size |
integer |
query |
False |
Filter by security_settings.event_log_settings.max_size |
security_settings.event_log_settings.retention_method |
string |
query |
False |
Filter by security_settings.event_log_settings.retention_method |
security_settings.files_or_folders |
string |
query |
False |
Filter by security_settings.files_or_folders |
uuid |
string |
query |
False |
Filter by uuid |
svm.uuid |
string |
query |
False |
Filter by svm.uuid |
svm.name |
string |
query |
False |
Filter by svm.name |
central_access_policy_settings |
string |
query |
False |
Filter by central_access_policy_settings |
central_access_policy_staging_audit_type |
string |
query |
False |
Filter by central_access_policy_staging_audit_type |
name |
string |
query |
False |
Filter by name
|
extensions |
string |
query |
False |
Filter by extensions |
file_system_path |
string |
query |
False |
Filter by file_system_path |
ldap_path |
string |
query |
False |
Filter by ldap_path |
enabled |
boolean |
query |
False |
Filter by enabled |
index |
integer |
query |
False |
Filter by index |
version |
integer |
query |
False |
Filter by version |
registry_settings.refresh_time_interval |
string |
query |
False |
Filter by registry_settings.refresh_time_interval |
registry_settings.branchcache.supported_hash_version |
string |
query |
False |
Filter by registry_settings.branchcache.supported_hash_version |
registry_settings.branchcache.hash_publication_mode |
string |
query |
False |
Filter by registry_settings.branchcache.hash_publication_mode |
registry_settings.refresh_time_random_offset |
string |
query |
False |
Filter by registry_settings.refresh_time_random_offset |
fields |
array[string] |
query |
False |
Specify the fields to return. |
return_records |
boolean |
query |
False |
The default is true for GET calls. When set to false, only the number of records is returned.
|
return_timeout |
integer |
query |
False |
The number of seconds to allow the call to execute before returning. When iterating over a collection, the default is 15 seconds. ONTAP returns earlier if either max records or the end of the collection is reached.
|
max_records |
integer |
query |
False |
Limit the number of records returned. |
order_by |
array[string] |
query |
False |
Order results by specified fields and optional [asc |
Response
Status: 200, Ok
Name | Type | Description |
---|---|---|
_links |
||
num_records |
integer |
Number of central access rules. |
records |
Example response
{
"_links": {
"next": {
"href": "/api/resourcelink"
},
"self": {
"href": "/api/resourcelink"
}
},
"num_records": 1,
"records": [
{
"svm": {
"_links": {
"self": {
"href": "/api/resourcelink"
}
},
"name": "svm1",
"uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
},
"to_be_applied": {
"access_policies": [
{
"create_time": "2018-01-01 11:00:00 -0500",
"description": "policy #1",
"member_rules": [
"r1",
"r2"
],
"name": "p1",
"sid": "S-1-5-21-256008430-3394229847-3930036330-1001",
"svm": {
"_links": {
"self": {
"href": "/api/resourcelink"
}
},
"name": "svm1",
"uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
},
"update_time": "2018-01-01 11:00:00 -0500"
}
],
"access_rules": [
{
"create_time": "2018-01-01 11:00:00 -0500",
"current_permission": "O:SYG:SYD:AR(A;;FA;;;WD)",
"description": "rule #1",
"name": "p1",
"proposed_permission": "O:SYG:SYD:(A;;FA;;;OW)(A;;FA;;;BA)(A;;FA;;;SY)",
"resource_criteria": "department",
"svm": {
"_links": {
"self": {
"href": "/api/resourcelink"
}
},
"name": "svm1",
"uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
},
"update_time": "2018-01-01 11:00:00 -0500"
}
],
"objects": [
{
"central_access_policy_settings": [
"p1",
"p2"
],
"central_access_policy_staging_audit_type": "none",
"extensions": [
"audit",
"security"
],
"file_system_path": "\\test.com\\SysVol\\test.com\\policies\\{42474212-3f9d-4489-ae01-6fcf4f805d4c}",
"index": 1,
"ldap_path": "cn={42474212-3f9d-4489-ae01-6fcf4f805d4c},cn=policies,cn=system,DC=TEST,DC=COM",
"link": "domain",
"name": "test_policy",
"registry_settings": {
"branchcache": {
"hash_publication_mode": "disabled",
"supported_hash_version": "version1"
},
"refresh_time_interval": "P15M",
"refresh_time_random_offset": "P1D"
},
"security_settings": {
"event_audit_settings": {
"logon_type": "failure",
"object_access_type": "failure"
},
"event_log_settings": {
"max_size": 2048,
"retention_method": "do_not_overwrite"
},
"files_or_folders": [
"/vol1/home",
"/vol1/dir1"
],
"kerberos": {
"max_clock_skew": "P15M",
"max_renew_age": "P2D",
"max_ticket_age": "P24H"
},
"privilege_rights": {
"change_notify_users": [
"usr1",
"usr2"
],
"security_privilege_users": [
"usr1",
"usr2"
],
"take_ownership_users": [
"usr1",
"usr2"
]
},
"restrict_anonymous": {
"combined_restriction_for_anonymous_user": "no_access"
},
"restricted_groups": [
"test_grp1",
"test_grp2"
]
},
"svm": {
"_links": {
"self": {
"href": "/api/resourcelink"
}
},
"name": "svm1",
"uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
},
"uuid": "42474212-3f9d-4489-ae01-6fcf4f805d4c",
"version": 7
}
],
"restricted_groups": [
{
"group_name": "test_group",
"link": "domain",
"members": [
"DOMAIN/test_user",
"DOMAIN/user2"
],
"memberships": [
"DOMAIN/AdministratorGrp",
"DOMAIN/deptMark"
],
"policy_name": "test_policy",
"svm": {
"_links": {
"self": {
"href": "/api/resourcelink"
}
},
"name": "svm1",
"uuid": "02c9e252-41be-11e9-81d5-00a0986138f7"
},
"version": 7
}
]
}
}
]
}
Error
Status: Default, Error
Name | Type | Description |
---|---|---|
error |
Example error
{
"error": {
"arguments": [
{
"code": "string",
"message": "string"
}
],
"code": "4",
"message": "entry doesn't exist",
"target": "uuid"
}
}