All Products
Search
Document Center

Identity as a Service:ListConditionalAccessPolicies

Last Updated:Sep 20, 2026

Lists conditional access policies.

Operation description

Queries conditional access policies by page.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

eiam:ListConditionalAccessPolicies

list

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*

None None

Request parameters

Parameter

Type

Required

Description

Example

InstanceId

string

Yes

The instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

NextToken

string

No

The pagination token for the next page.

NTxxxxxexample

MaxResults

integer

No

The number of rows per page in a paged query.

20

PreviousToken

string

No

The pagination token for the previous page.

PTxxxxxexample

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID.

0441BD79-92F3-53AA-8657-F8CE4A2B912A

TotalCount

integer

The total number of entries in the list.

100

NextToken

string

The query token (Token) value returned by this call.

NTxxxexample

ConditionalAccessPolicies

array<object>

The collection of conditional access policies.

array<object>

InstanceId

string

The instance ID.

idaas_ksvv5c7f2l6uzh6oqspeks23ni

ConditionalAccessPolicyId

string

The conditional access policy ID.

cp_xxxxx

ConditionalAccessPolicyName

string

The Policy Name of the conditional access policy.

MyPolicy

Description

string

The description of the conditional access policy.

My policy description

ConditionalAccessPolicyType

string

The type of the conditional access policy.

arn:alibaba:idaas:authn:access:policy:system

Status

string

The enabled or disabled status of the conditional access policy.

disabled

DecisionType

string

The decision type of the conditional access policy.

enforcement

EvaluateAt

string

The evaluation point of the conditional access policy.

arn:alibaba:idaas:authn:access:rule:eval_at:after_step1

Priority

integer

The priority. Valid values: 1 to 100.

1

DecisionConfig

object

The decision action configuration of the conditional access policy.

Effect

string

The decision action of the conditional access policy. Valid values:

  • deny: Deny.

  • allow: Allow.

deny

MfaType

string

The MFA type of the conditional access policy.

directly_access

MfaAuthenticationIntervalSeconds

integer

The MFA re-authentication interval of the conditional access policy, in seconds. Valid values: 300 to 86400.

300

MfaAuthenticationMethods

array

The MFA methods allowed by the conditional access policy.

string

The MFA method allowed by the conditional access policy. Valid values:

  • ia_otp_sms: SMS verification code.

  • ia_otp_email: Email verification code.

  • ia_totp: OTP dynamic password.

  • ia_webauthn: WebAuthn.

ia_otp_email

ActiveSessionReuseStatus

string

Indicates whether secondary authentication session reuse is enabled.

disabled

ConditionsConfig

object

The conditions configuration of the conditional access policy.

Applications

object

The target applications of the conditional access policy.

IncludeApplications

array

The included applications.

string

The application ID.

app_xxxxx

ExcludeApplications

array

The excluded applications.

string

The application ID.

app_xxxxx

Users

object

The target users of the conditional access policy.

IncludeUsers

array

The included users.

string

The user ID.

user_xxxxx

ExcludeUsers

array

The excluded users.

string

The user ID.

user_xxxxx

IncludeGroups

array

The included user groups.

string

The user group ID.

group_xxxxx

ExcludeGroups

array

The excluded user groups.

string

The user group ID.

group_xxxxx

IncludeOrganizationalUnits

array

The included organizational units.

string

The organizational unit ID.

ou_xxxxx

ExcludeOrganizationalUnits

array

The excluded organizational units.

string

The organizational unit ID.

ou_xxxxx

NetworkZones

object

The network zones of the conditional access policy.

IncludeNetworkZones

array

The included network zones.

string

The ID of the included network zone.

network_xxxxx

ExcludeNetworkZones

array

The excluded network zones.

string

The ID of the excluded network zone.

network_xxxxx

CreateTime

integer

The creation time. The value is a UNIX timestamp in milliseconds.

1741857554000

LastUpdatedTime

integer

The update time. This value is a UNIX timestamp. Unit: milliseconds.

1741857554000

PreviousToken

string

The pagination token for the previous page.

PTxxxxxexample

Examples

Success response

JSON format

{
  "RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A",
  "TotalCount": 100,
  "NextToken": "NTxxxexample",
  "ConditionalAccessPolicies": [
    {
      "InstanceId": "idaas_ksvv5c7f2l6uzh6oqspeks23ni",
      "ConditionalAccessPolicyId": "cp_xxxxx",
      "ConditionalAccessPolicyName": "我的策略",
      "Description": "我的策略描述",
      "ConditionalAccessPolicyType": "arn:alibaba:idaas:authn:access:policy:system",
      "Status": "disabled",
      "DecisionType": "enforcement",
      "EvaluateAt": "arn:alibaba:idaas:authn:access:rule:eval_at:after_step1",
      "Priority": 1,
      "DecisionConfig": {
        "Effect": "deny",
        "MfaType": "directly_access",
        "MfaAuthenticationIntervalSeconds": 300,
        "MfaAuthenticationMethods": [
          "ia_otp_email"
        ],
        "ActiveSessionReuseStatus": "disabled"
      },
      "ConditionsConfig": {
        "Applications": {
          "IncludeApplications": [
            "app_xxxxx"
          ],
          "ExcludeApplications": [
            "app_xxxxx"
          ]
        },
        "Users": {
          "IncludeUsers": [
            "user_xxxxx"
          ],
          "ExcludeUsers": [
            "user_xxxxx"
          ],
          "IncludeGroups": [
            "group_xxxxx"
          ],
          "ExcludeGroups": [
            "group_xxxxx"
          ],
          "IncludeOrganizationalUnits": [
            "ou_xxxxx"
          ],
          "ExcludeOrganizationalUnits": [
            "ou_xxxxx"
          ]
        },
        "NetworkZones": {
          "IncludeNetworkZones": [
            "network_xxxxx"
          ],
          "ExcludeNetworkZones": [
            "network_xxxxx"
          ]
        }
      },
      "CreateTime": 1741857554000,
      "LastUpdatedTime": 1741857554000
    }
  ],
  "PreviousToken": "PTxxxxxexample"
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.