openapi: 3.0.0 info: version: '2017-10-01' x-release: v4 title: 'Amazon WorkMail #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.PutAccessControlRule API' description:

WorkMail is a secure, managed business email and calendaring service with support for existing desktop and mobile email clients. You can access your email, contacts, and calendars using Microsoft Outlook, your browser, or other native iOS and Android email applications. You can integrate WorkMail with your existing corporate directory and control both the keys that encrypt your data and the location in which your data is stored.

The WorkMail API is designed for the following scenarios:

All WorkMail API operations are Amazon-authenticated and certificate-signed. They not only require the use of the AWS SDK, but also allow for the exclusive use of AWS Identity and Access Management users and roles to help facilitate access, trust, and permission policies. By creating a role and allowing an IAM user to access the WorkMail site, the IAM user gains full administrative visibility into the entire WorkMail organization (or as set in the IAM policy). This includes, but is not limited to, the ability to create, update, and delete users, groups, and resources. This allows developers to perform the scenarios listed above, as well as give users the ability to grant access on a selective basis using the IAM model.

x-logo: url: https://twitter.com/awscloud/profile_image?size=original backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: workmail x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/workmail-2017-10-01.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://workmail.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon WorkMail multi-region endpoint - url: https://workmail.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon WorkMail multi-region endpoint - url: http://workmail.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia) - url: https://workmail.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=WorkMailService.PutAccessControlRule' paths: /#X-Amz-Target=WorkMailService.PutAccessControlRule: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: PutAccessControlRule description: Adds a new access control rule for the specified organization. The rule allows or denies access to the organization for the specified IPv4 addresses, access protocol actions, user IDs and impersonation IDs. Adding a new rule with the same name as an existing rule replaces the older rule. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/PutAccessControlRuleResponse' '480': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '481': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' '482': description: EntityNotFoundException content: application/json: schema: $ref: '#/components/schemas/EntityNotFoundException' '483': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '484': description: OrganizationNotFoundException content: application/json: schema: $ref: '#/components/schemas/OrganizationNotFoundException' '485': description: OrganizationStateException content: application/json: schema: $ref: '#/components/schemas/OrganizationStateException' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PutAccessControlRuleRequest' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - WorkMailService.PutAccessControlRule summary: Amazon WorkMail Put Access Control Rule tags: - '#X Amz Target=WorkMailService.PutAccessControlRule' components: schemas: ResourceNotFoundException: {} PutAccessControlRuleResponse: type: object properties: {} AccessControlRuleName: type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 64 PutAccessControlRuleRequest: type: object required: - Name - Effect - Description - OrganizationId title: PutAccessControlRuleRequest properties: Name: allOf: - $ref: '#/components/schemas/AccessControlRuleName' - description: The rule name. Effect: allOf: - $ref: '#/components/schemas/AccessControlRuleEffect' - description: The rule effect. Description: allOf: - $ref: '#/components/schemas/AccessControlRuleDescription' - description: The rule description. IpRanges: allOf: - $ref: '#/components/schemas/IpRangeList' - description: IPv4 CIDR ranges to include in the rule. NotIpRanges: allOf: - $ref: '#/components/schemas/IpRangeList' - description: IPv4 CIDR ranges to exclude from the rule. Actions: allOf: - $ref: '#/components/schemas/ActionsList' - description: Access protocol actions to include in the rule. Valid values include ActiveSync, AutoDiscover, EWS, IMAP, SMTP, WindowsOutlook, and WebMail. NotActions: allOf: - $ref: '#/components/schemas/ActionsList' - description: Access protocol actions to exclude from the rule. Valid values include ActiveSync, AutoDiscover, EWS, IMAP, SMTP, WindowsOutlook, and WebMail. UserIds: allOf: - $ref: '#/components/schemas/UserIdList' - description: User IDs to include in the rule. NotUserIds: allOf: - $ref: '#/components/schemas/UserIdList' - description: User IDs to exclude from the rule. OrganizationId: allOf: - $ref: '#/components/schemas/OrganizationId' - description: The identifier of the organization. ImpersonationRoleIds: allOf: - $ref: '#/components/schemas/ImpersonationRoleIdList' - description: Impersonation role IDs to include in the rule. NotImpersonationRoleIds: allOf: - $ref: '#/components/schemas/ImpersonationRoleIdList' - description: Impersonation role IDs to exclude from the rule. ActionsList: type: array items: $ref: '#/components/schemas/AccessControlRuleAction' minItems: 0 maxItems: 10 OrganizationStateException: {} OrganizationId: type: string pattern: ^m-[0-9a-f]{32}$ minLength: 34 maxLength: 34 IpRange: type: string pattern: ^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])/([0-9]|[12][0-9]|3[0-2])$ minLength: 1 maxLength: 18 InvalidParameterException: {} OrganizationNotFoundException: {} AccessControlRuleAction: type: string pattern: '[a-zA-Z]+' minLength: 1 maxLength: 64 ImpersonationRoleId: type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 64 IpRangeList: type: array items: $ref: '#/components/schemas/IpRange' minItems: 0 maxItems: 1024 LimitExceededException: {} ImpersonationRoleIdList: type: array items: $ref: '#/components/schemas/ImpersonationRoleId' minItems: 0 maxItems: 10 AccessControlRuleEffect: type: string enum: - ALLOW - DENY AccessControlRuleDescription: type: string pattern: '[\u0020-\u00FF]+' minLength: 0 maxLength: 255 WorkMailIdentifier: type: string minLength: 12 maxLength: 256 EntityNotFoundException: {} UserIdList: type: array items: $ref: '#/components/schemas/WorkMailIdentifier' minItems: 0 maxItems: 10 parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/workmail/ x-hasEquivalentPaths: true