An Azure service that provides a hybrid, multi-cloud management platform for APIs.
Welcome to Microsoft Q&A
Hello @Neel Manthani I hope you are doing well,
The reason you are not seeing the condition field in the API response is due to the specific API version you are targeting.
While API version 2022-04-01 was the milestone release that brought Attribute-Based Access Control (ABAC) conditions to General Availability for Role Assignments, the schema for Role Definitions did not immediately expose the corresponding built-in condition properties.
According to the Azure REST API changelog, the condition and conditionVersion fields were not added to the Microsoft.Authorization/roleDefinitions schema until the 2022-05-01-preview API version. Resource Graph Explorer uses newer/internal API versions by default, which is why you can see the field there but not in your Terraform outputs.
How to resolve this: Update your azapi Terraform configuration to use the newer API version:
Change your type string to Microsoft.Authorization/roleDefinitions@2022-05-01-preview (or a newer available version).
Note that the condition field is not located at the root of properties. Because a role definition can have multiple permission sets, the condition is nested inside the permissions array.
Once you update the API version, you will find the condition field in the retrieved JSON object at this path: properties.permissions[0].condition
😊 If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily.