POST | Activate access policy

Prev Next

Description

Activate an access policy in PAM Core. An active policy applies the access it defines to the resources matched by its criteria.

This action is the only way to set a policy as active. The active field can't be sent in POST | Create access policy, PUT | Update access policy by [id], or PATCH | Partially update access policy by [id].

Attention

Activating a policy grants the access it defines to every user matched by its criteria. Confirm the policy's criteria and its password and session rules before activating it.


Prerequisites

  • An application with the Access Policy (V2) authorization granted by the administrator in A2A, and its PAM resource permission set to Read and write. For more information, access How to manage authorizations in A2A.
  • A valid OAuth 2.0 access token. For more information, access How to authenticate an application in A2A.
  • The access policy must be inactive. Activating an already active policy returns 409.
Info

An access token carries only the authorizations that existed when it was generated. After the administrator enables Access Policy (V2), generate a new token for the application, an existing token won't gain the new authorization.


Request

POST /api/v2/pam/access-policies/{id}/activate

Path parameters

Field Type Required Description
id integer Yes Unique identification code of the access policy. Note: this value is assigned by Segura® in POST | Create access policy.

The request has no body.


Example request

POST {{url}}/api/v2/pam/access-policies/3001/activate


Response

HTTP/1.1 204 No Content

The response has no body. To confirm the new state, retrieve the policy with GET | List an access policy by [id].


Errors

HTTP code Message Possible cause Solution
401 api.auth.token.invalid The access token is missing or has expired. Request a new access token.
403 api.permission.denied The authorization doesn't have permission to update access policies. Ask the administrator to check the Access Policy (V2) authorization and the PAM resource permission in A2A, then generate a new token.
404 api.resource.not_found The access policy doesn't exist, or it's outside the scope of the authorization. Check the identification code sent in the path.
409 api.resource.conflict.already_active The access policy is already active. No action is needed, the policy is already in the requested state.
429 rate_limit_exceeded The request rate limit was exceeded. Reduce the request rate and try again.
500 api.internal.error Internal server error. Contact the Segura® support team.

Example error response

409 the policy is already active:

{
    "error": {
        "code": "api.resource.conflict.already_active",
        "message": "Access policy is already active."
    }
}
Info

This action isn't idempotent. Repeating it on a policy that's already active returns 409 rather than 204. Retrieve the policy's current state before retrying a request whose outcome you're unsure of.

For authentication error messages and the 403 versus 404 policy, access API v2 - Conventions and shared behaviors.