Skip to main content

RequestOnBehalfOfConfig2

Properties

NameTypeDescriptionNotes
allowRequestOnBehalfOfAnyoneByAnyone(optional) booleanIf this is true, anyone can request access for anyone.[default to false]
allowRequestOnBehalfOfEmployeeByManager(optional) booleanIf this is true, a manager can request access for his or her direct reports.[default to false]
allowRequestOnBehalfOfForMachineIdentity(optional) booleanIf this is true, anyone can request access on behalf of machine identities. Machine access request authorization is evaluated as follows: 1. If this flag is true, any requester is allowed. 2. Else if allowRequestForMachineByOwner is true, the requester must be an admin or a primary/secondary owner of every requested machine identity. 3. Else admins are still allowed; non-admins receive 403.[default to true]
allowRequestForMachineByOwner(optional) booleanWhen allowRequestOnBehalfOfForMachineIdentity is false and this flag is true, only admins and primary/secondary owners of the requested machine identities may submit machine access requests. Defaults to false (opt-in).[default to false]