Thank you for posting this in Microsoft Q&A.
I understand that you are trying to create an Azure role assignment for an Azure AD group with eligibility that should be valid for 4 hours, but you are getting an error: "ERROR: usage error: --assignee-object-id GUID --assignee-principal-type TYPE."
The command "az role assignment" will be used to create Azure roles. I have tried your Azure CLI command in my environment and noticed the same error in my environment as well.
As per this document, we have to use the "assignee-principal-type" parameter only with the "assignee-object-id" parameter, but you are using "assignee" and "assignee-principal-type" parameters at the same command, which causes an error.
Try to run the Azure CLI command as follows:
az role assignment create --assignee f531dc02-5610-4d18-b5bf-59ba8b982acb --role Contributor --scope /subscriptions/811174b4-ff1b-000013917f8ec4e
The "condition" parameter is only used for providing more fine-grained access control. For example, you can add a condition that requires an object to have a specific tag to read the object.
In the Microsoft admin center/Azure portal, we have a feature called Privileged Identity Management (PIM). With Microsoft Entra PIM, your end-users must activate an eligible role assignment to get permission to perform certain actions. Using conditions in Microsoft Entra PIM enables you not only to limit a user's role permissions to a resource using fine-grained conditions but also to use Microsoft Entra PIM to secure the role assignment with a time-bound setting, an approval workflow, an audit trail, and so on.
Please follow the steps mentioned in this document to create an Azure role assignment for an Azure AD group with eligibility that should be valid for 4 hours.
As of now Privileged Identity Management supports only Azure Resource Manager (ARM) API commands to manage Azure resource roles.
Hope this helps. Do let us know if you any further queries.
Thanks,
Navya.
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.