blob: 4e4437200d26afc17cff2be38eb79d4b24925cf1 [file] [log] [blame]
{
"name" : "permit-admin-only-using-condition",
"policies" : [
{
"name" : "Subject with role Administrator has access to everything",
"conditions" : [
{
"name":"",
"condition" : "match.single(subject.attributes('https://acs.attributes.int', 'role'), 'administrator')"
}
],
"effect" : "PERMIT"
},
{
"name" : "DENY to everyone else",
"effect" : "DENY"
}
]
}