Specifies whether users can use granular delegated admin privileges (GDAP) to sign-in and access resources in other organizations.
Default value is false.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
CreateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-BodyParameter
crossTenantAccessPolicyConfigurationPartner
To construct, see NOTES section for BODYPARAMETER properties and create a hash table.
Identifies whether a tenant is a member of a multitenant organization.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
CreateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-IsServiceProvider
Identifies whether the partner-specific configuration is a Cloud Service Provider for your organization.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Default value:
False
Supports wildcards:
False
DontShow:
False
Parameter sets
CreateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-M365Capabilities
Defines the partner-specific Microsoft 365 cross-tenant capabilities for inbound access from the partner organization.
To construct, see NOTES section for M365CAPABILITIES properties and create a hash table.
crossTenantAccessPolicyM365CollaborationInboundSetting
To construct, see NOTES section for M365COLLABORATIONINBOUND properties and create a hash table.
crossTenantAccessPolicyM365CollaborationOutboundSetting
To construct, see NOTES section for M365COLLABORATIONOUTBOUND properties and create a hash table.
Runs the command in a mode that only reports what would happen without performing the actions.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Supports wildcards:
False
DontShow:
False
Aliases:
wi
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable,
-InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable,
-ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see
about_CommonParameters.
To create the parameters described below, construct a hash table containing the appropriate properties.
For information on hash tables, run Get-Help about_Hash_Tables.
APPSERVICECONNECTINBOUND <IMicrosoftGraphCrossTenantAccessPolicyAppServiceConnectSetting>: crossTenantAccessPolicyAppServiceConnectSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
AUTOMATICUSERCONSENTSETTINGS <IMicrosoftGraphInboundOutboundPolicyConfiguration>: inboundOutboundPolicyConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[InboundAllowed <Boolean?>]: Defines whether external users coming inbound are allowed.
[OutboundAllowed <Boolean?>]: Defines whether internal users are allowed to go outbound.
B2BCOLLABORATIONINBOUND <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>: crossTenantAccessPolicyB2BSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
B2BCOLLABORATIONOUTBOUND <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>: crossTenantAccessPolicyB2BSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
B2BDIRECTCONNECTINBOUND <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>: crossTenantAccessPolicyB2BSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
B2BDIRECTCONNECTOUTBOUND <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>: crossTenantAccessPolicyB2BSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
BODYPARAMETER <IMicrosoftGraphCrossTenantAccessPolicyConfigurationPartner>: crossTenantAccessPolicyConfigurationPartner
[(Any) <Object>]: This indicates any property can be added to this object.
[DeletedDateTime <DateTime?>]: Shows the last date and time the policy was deleted.
[AppServiceConnectInbound <IMicrosoftGraphCrossTenantAccessPolicyAppServiceConnectSetting>]: crossTenantAccessPolicyAppServiceConnectSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
[AutomaticUserConsentSettings <IMicrosoftGraphInboundOutboundPolicyConfiguration>]: inboundOutboundPolicyConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[InboundAllowed <Boolean?>]: Defines whether external users coming inbound are allowed.
[OutboundAllowed <Boolean?>]: Defines whether internal users are allowed to go outbound.
[B2BCollaborationInbound <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>]: crossTenantAccessPolicyB2BSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[B2BCollaborationOutbound <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>]: crossTenantAccessPolicyB2BSetting
[B2BDirectConnectInbound <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>]: crossTenantAccessPolicyB2BSetting
[B2BDirectConnectOutbound <IMicrosoftGraphCrossTenantAccessPolicyB2BSetting>]: crossTenantAccessPolicyB2BSetting
[BlockServiceProviderOutboundAccess <Boolean?>]: Specifies whether users can use granular delegated admin privileges (GDAP) to sign-in and access resources in other organizations.
Default value is false.
[IdentitySynchronization <IMicrosoftGraphCrossTenantIdentitySyncPolicyPartner>]: crossTenantIdentitySyncPolicyPartner
[(Any) <Object>]: This indicates any property can be added to this object.
[DeletedDateTime <DateTime?>]: Shows the last date and time the policy was deleted.
[DisplayName <String>]: Display name for the cross-tenant user and group synchronization policy.
Use the name of the partner Microsoft Entra tenant to easily identify the policy.
Optional.
[ExternalCloudAuthorizedApplicationId <String>]:
[GroupSyncInbound <IMicrosoftGraphCrossTenantGroupSyncInbound>]: crossTenantGroupSyncInbound
[(Any) <Object>]: This indicates any property can be added to this object.
[IsSyncAllowed <Boolean?>]: Defines whether group objects should be synchronized from the partner tenant.
false stops any current group synchronization from the source tenant to the target tenant.
This property has no impact on existing groups that were synchronized.
[RoleEnabledGroupSyncInbound <IMicrosoftGraphCrossTenantRoleEnabledGroupSyncInbound>]: crossTenantRoleEnabledGroupSyncInbound
[(Any) <Object>]: This indicates any property can be added to this object.
[IsSyncAllowed <Boolean?>]:
[TenantId <String>]: Tenant identifier for the partner Microsoft Entra organization.
Key.
Read-only.
[UserSyncInbound <IMicrosoftGraphCrossTenantUserSyncInbound>]: crossTenantUserSyncInbound
[(Any) <Object>]: This indicates any property can be added to this object.
[IsSyncAllowed <Boolean?>]: Defines whether user objects should be synchronized from the partner tenant.
false causes any current user synchronization from the source tenant to the target tenant to stop.
This property has no impact on existing users who have already been synchronized.
[InboundTrust <IMicrosoftGraphCrossTenantAccessPolicyInboundTrust>]: crossTenantAccessPolicyInboundTrust
[(Any) <Object>]: This indicates any property can be added to this object.
[IsCompliantDeviceAccepted <Boolean?>]: Specifies whether compliant devices from external Microsoft Entra organizations are trusted.
[IsHybridAzureAdJoinedDeviceAccepted <Boolean?>]: Specifies whether Microsoft Entra hybrid joined devices from external Microsoft Entra organizations are trusted.
[IsMfaAccepted <Boolean?>]: Specifies whether MFA from external Microsoft Entra organizations is trusted.
[IsInMultiTenantOrganization <Boolean?>]: Identifies whether a tenant is a member of a multitenant organization.
[IsServiceProvider <Boolean?>]: Identifies whether the partner-specific configuration is a Cloud Service Provider for your organization.
[M365Capabilities <IMicrosoftGraphM365CapabilityBase[]>]: Defines the partner-specific Microsoft 365 cross-tenant capabilities for inbound access from the partner organization.
[Id <String>]: The unique identifier for an entity.
Read-only.
[InboundAccess <IMicrosoftGraphM365CapabilityInboundAccess>]: m365CapabilityInboundAccess
[(Any) <Object>]: This indicates any property can be added to this object.
[IsAllowed <Boolean?>]: Indicates whether this capability should be allowed or blocked for inbound access.
[ResourceScopes <IMicrosoftGraphM365CapabilityResourceScopes>]: m365CapabilityResourceScopes
[(Any) <Object>]: This indicates any property can be added to this object.
[Excluded <IMicrosoftGraphM365CapabilityResourceScope[]>]: Resources to exclude from the scope.
If a resource appears in both included and excluded, the excluded property takes precedence.
[ResourceId <String>]: The ID of the resource to modify.
The value is either All, to apply the capability to all resources of the type specified by resourceType (all users or all groups), or the GUID of a specific user or group.
[ResourceType <String>]: m365ResourceType
[Included <IMicrosoftGraphM365CapabilityResourceScope[]>]: Resources to include in the scope.
[LastModifiedDateTime <DateTime?>]: The automatically updated last modified timestamp for the capability.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2024, is 2024-01-01T00:00:00Z.
[Name <String>]: The name or identifier of the capability.
Key.
[M365CollaborationInbound <IMicrosoftGraphCrossTenantAccessPolicyM365CollaborationInboundSetting>]: crossTenantAccessPolicyM365CollaborationInboundSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Users <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[M365CollaborationOutbound <IMicrosoftGraphCrossTenantAccessPolicyM365CollaborationOutboundSetting>]: crossTenantAccessPolicyM365CollaborationOutboundSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[ServiceProviderConstraints <IMicrosoftGraphServiceProviderConstraints>]: serviceProviderConstraints
[(Any) <Object>]: This indicates any property can be added to this object.
[DeletedDateTime <DateTime?>]: Shows the last date and time the policy was deleted.
[Id <String>]:
[TenantId <String>]: The tenant identifier for the partner Microsoft Entra organization.
Read-only.
Key.
[TenantRestrictions <IMicrosoftGraphCrossTenantAccessPolicyTenantRestrictions>]: crossTenantAccessPolicyTenantRestrictions
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[Devices <IMicrosoftGraphDevicesFilter>]: devicesFilter
[(Any) <Object>]: This indicates any property can be added to this object.
[Mode <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Rule <String>]: Defines the rule to filter the devices.
For example, device.deviceAttribute2 -eq 'PrivilegedAccessWorkstation'.
IDENTITYSYNCHRONIZATION <IMicrosoftGraphCrossTenantIdentitySyncPolicyPartner>: crossTenantIdentitySyncPolicyPartner
[(Any) <Object>]: This indicates any property can be added to this object.
[DeletedDateTime <DateTime?>]: Shows the last date and time the policy was deleted.
[DisplayName <String>]: Display name for the cross-tenant user and group synchronization policy.
Use the name of the partner Microsoft Entra tenant to easily identify the policy.
Optional.
[ExternalCloudAuthorizedApplicationId <String>]:
[GroupSyncInbound <IMicrosoftGraphCrossTenantGroupSyncInbound>]: crossTenantGroupSyncInbound
[(Any) <Object>]: This indicates any property can be added to this object.
[IsSyncAllowed <Boolean?>]: Defines whether group objects should be synchronized from the partner tenant.
false stops any current group synchronization from the source tenant to the target tenant.
This property has no impact on existing groups that were synchronized.
[RoleEnabledGroupSyncInbound <IMicrosoftGraphCrossTenantRoleEnabledGroupSyncInbound>]: crossTenantRoleEnabledGroupSyncInbound
[(Any) <Object>]: This indicates any property can be added to this object.
[IsSyncAllowed <Boolean?>]:
[TenantId <String>]: Tenant identifier for the partner Microsoft Entra organization.
Key.
Read-only.
[UserSyncInbound <IMicrosoftGraphCrossTenantUserSyncInbound>]: crossTenantUserSyncInbound
[(Any) <Object>]: This indicates any property can be added to this object.
[IsSyncAllowed <Boolean?>]: Defines whether user objects should be synchronized from the partner tenant.
false causes any current user synchronization from the source tenant to the target tenant to stop.
This property has no impact on existing users who have already been synchronized.
INBOUNDTRUST <IMicrosoftGraphCrossTenantAccessPolicyInboundTrust>: crossTenantAccessPolicyInboundTrust
[(Any) <Object>]: This indicates any property can be added to this object.
[IsCompliantDeviceAccepted <Boolean?>]: Specifies whether compliant devices from external Microsoft Entra organizations are trusted.
[IsHybridAzureAdJoinedDeviceAccepted <Boolean?>]: Specifies whether Microsoft Entra hybrid joined devices from external Microsoft Entra organizations are trusted.
[IsMfaAccepted <Boolean?>]: Specifies whether MFA from external Microsoft Entra organizations is trusted.
M365CAPABILITIES <IMicrosoftGraphM365CapabilityBase[]>: Defines the partner-specific Microsoft 365 cross-tenant capabilities for inbound access from the partner organization.
[Id <String>]: The unique identifier for an entity.
Read-only.
[InboundAccess <IMicrosoftGraphM365CapabilityInboundAccess>]: m365CapabilityInboundAccess
[(Any) <Object>]: This indicates any property can be added to this object.
[IsAllowed <Boolean?>]: Indicates whether this capability should be allowed or blocked for inbound access.
[ResourceScopes <IMicrosoftGraphM365CapabilityResourceScopes>]: m365CapabilityResourceScopes
[(Any) <Object>]: This indicates any property can be added to this object.
[Excluded <IMicrosoftGraphM365CapabilityResourceScope[]>]: Resources to exclude from the scope.
If a resource appears in both included and excluded, the excluded property takes precedence.
[ResourceId <String>]: The ID of the resource to modify.
The value is either All, to apply the capability to all resources of the type specified by resourceType (all users or all groups), or the GUID of a specific user or group.
[ResourceType <String>]: m365ResourceType
[Included <IMicrosoftGraphM365CapabilityResourceScope[]>]: Resources to include in the scope.
[LastModifiedDateTime <DateTime?>]: The automatically updated last modified timestamp for the capability.
The timestamp type represents date and time information using ISO 8601 format and is always in UTC.
For example, midnight UTC on Jan 1, 2024, is 2024-01-01T00:00:00Z.
[Name <String>]: The name or identifier of the capability.
Key.
M365COLLABORATIONINBOUND <IMicrosoftGraphCrossTenantAccessPolicyM365CollaborationInboundSetting>: crossTenantAccessPolicyM365CollaborationInboundSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[Users <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
M365COLLABORATIONOUTBOUND <IMicrosoftGraphCrossTenantAccessPolicyM365CollaborationOutboundSetting>: crossTenantAccessPolicyM365CollaborationOutboundSetting
[(Any) <Object>]: This indicates any property can be added to this object.
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
SERVICEPROVIDERCONSTRAINTS <IMicrosoftGraphServiceProviderConstraints>: serviceProviderConstraints
[(Any) <Object>]: This indicates any property can be added to this object.
[DeletedDateTime <DateTime?>]: Shows the last date and time the policy was deleted.
[Id <String>]:
TENANTRESTRICTIONS <IMicrosoftGraphCrossTenantAccessPolicyTenantRestrictions>: crossTenantAccessPolicyTenantRestrictions
[(Any) <Object>]: This indicates any property can be added to this object.
[Applications <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[(Any) <Object>]: This indicates any property can be added to this object.
[AccessType <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Targets <IMicrosoftGraphCrossTenantAccessPolicyTarget[]>]: Specifies whether to target users, groups, or applications with this rule.
[Target <String>]: Defines the target for cross-tenant access policy settings and can have one of the following values: The unique identifier of the user, group, or application AllUsers AllApplications - Refers to any Microsoft cloud application.
Office365 - Includes the applications mentioned as part of the Office 365 suite.
[TargetType <String>]: crossTenantAccessPolicyTargetType
[UsersAndGroups <IMicrosoftGraphCrossTenantAccessPolicyTargetConfiguration>]: crossTenantAccessPolicyTargetConfiguration
[Devices <IMicrosoftGraphDevicesFilter>]: devicesFilter
[(Any) <Object>]: This indicates any property can be added to this object.
[Mode <String>]: crossTenantAccessPolicyTargetConfigurationAccessType
[Rule <String>]: Defines the rule to filter the devices.
For example, device.deviceAttribute2 -eq 'PrivilegedAccessWorkstation'.