Retrieves a direct assignment of a user or group to an application. If the user doesn’t have a direct assignment to the application, the user may still have access to the application through a group. Therefore, don’t use this API to test access to an application for a user. Instead use list_application_assignments_for_principal
.
See https://www.paws-r-sdk.com/docs/ssoadmin_describe_application_assignment/ for full documentation.
ssoadmin_describe_application_assignment(
ApplicationArn,
PrincipalId,
PrincipalType
)
[required] Specifies the ARN of the application. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces in the Amazon Web Services General Reference.
[required] An identifier for an object in IAM Identity Center, such as a user or group. PrincipalIds are GUIDs (For example, f81d4fae-7dec-11d0-a765-00a0c91e6bf6). For more information about PrincipalIds in IAM Identity Center, see the IAM Identity Center Identity Store API Reference.
[required] The entity type for which the assignment will be created.