Create an Asset Policy.

Adds a new Asset Policy resource.
The response body contains the new Asset Policy.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

New Asset Policy properties.

string
required
length between 1 and 255

The display name of the Asset Policy.

string
length between 0 and 64
^[a-zA-Z0-9_\\-]+$

The code name of the Asset Policy.

string
length ≤ 1000

The Asset Policy's comments.

boolean
Defaults to true

If true, users are restricted to accessing Assets within the scheduled hours. This setting cannot be enabled when require_approval is true.

string
enum
Defaults to global

If set to join, once the first user is in a session, subsequent users will be able to enter the session. The first user will receive a notification that another user has joined the session, but the first user will not have an opportunity to deny access before other user joins. Selecting the global value means that the behavior defined under Asset Management -> Assets will be used.

Allowed:
boolean
Defaults to false

This field is only valid if simultaneous_jumps is set to join; otherwise, this field should be set to false or left unset. If true, a user will be allowed to join a session that was started from another copy of a Jump Client in a different Asset Group. Session permissions will be based on the original Jump Client that started the session. If false, a user will not be allowed to join a session that was started from another copy of an Asset unless it is the same Asset Group.

string
enum
Defaults to global

If set to new_session, then a new independent session will start for each user which jumps to a specific RDP Asset, and the RDP configuration on the endpoint will control any further behavior regarding simultaneous RDP connections. Selecting the global value means that the behavior defined under Asset Management -> Assets will be used.

Allowed:
boolean
Defaults to true

If true, this will follow the global setting behavior for Remote RDP Assets defined under Asset Management -> Assets. If the global setting allows opening Remote RDP Assets with external tools, then users can open them. Otherwise, users cannot open them. If false, this will prevent users from opening them with external tools regardless of the global setting.

boolean
Defaults to true

If true, this will follow the global setting behavior for Shell sessions defined under Asset Management -> Assets. If the global setting allows opening Shell sessions with external tools, then users can open them. Otherwise, users cannot open them. If false, this will prevent users from opening them with external tools regardless of the global setting.

boolean
Defaults to false

If true, users are forcefully removed from sessions when the schedule does not permit access. This can only be set to true if schedule_enabled is also true.

string
enum
Defaults to none

Controls whether a user must provide context before starting a session on an Asset.

  • none — no context required.
  • ticket_id — user must enter a valid ticket ID that will be verified against the Ticket System configured on the Asset Management → Asset Policies page. The setting has no effect if a Ticket System is not configured.
  • justification — user must enter a written justification for starting the session, which is logged for auditing.

Replaces the legacy boolean ticket_id_required. The API still accepts ticket_id_required on ingress (trueticket_id, falsenone), but the field is no longer returned in responses.

Allowed:
boolean
Defaults to false

If true, users must have two-factor authentication enabled and must complete a two-factor challenge before starting a session.

boolean
Defaults to false

If true, an email notification is sent to the configured recipients when a session starts.

boolean
Defaults to false

If true, an email notification is sent to the configured recipients when a session ends.

notification_email_addresses
array of strings
length between 0 and 100
Defaults to []

The list of email addresses to which session start and session end notifications will be sent. Required only if one or more notifications are enabled. The site must have an SMTP server configured on the Management > Email Configuration page.

notification_email_addresses
string
length ≤ 255

The display name of the recipients shown to users. Required in POST only if one or more notifications are enabled.

string
Defaults to en-us

The language in which notification emails will be sent. Must be the locale code for one of the locales listed on the Localization → Languages page.

boolean
Defaults to false

If true, users must wait for approval from one of the approvers before they can start a session. This setting cannot be enabled when schedule_enabled is true.

int32
1 to 524160
Defaults to 480

The number of minutes a user is allowed to access the Asset after approval is granted. The maximum is 52 weeks in minutes.

string
enum
Defaults to requestor

The scope of access granted by approvals. If "requestor", only the requestor has access. If "anyone", anyone who is permitted to request access has access.

Allowed:
approval_email_addresses
array of strings
length between 0 and 100
Defaults to []

The list of email addresses to which approval requests will be sent. It is required only if approvals are enabled. The site must have an SMTP server configured on the Management > Email Configuration page.

approval_email_addresses
approval_user_ids
array of strings
length between 0 and 100
Defaults to []

The list of user ids to which approval requests will be sent. It is required only if approvals are enabled.

approval_user_ids
approval_team_ids
array of strings
length between 0 and 100
Defaults to []

The list of team ids to which approval requests will be sent. It is required only if approvals are enabled.

approval_team_ids
string
length ≤ 255

The display name of the approvers that requestors will see. It is required only if approvals are enabled.

string
Defaults to en-us

The language in which approval emails will be sent. Must be the locale code for one of the locales listed on the Localization → Languages page.

string
enum
Defaults to not_requestor

The scope of approval granted to approvers. If "not_requestor", then the approver cannot approve their own requests. If "anyone", anyone who is permitted to approve, can approve requests, including their own.

Allowed:
boolean
Defaults to false

If true, sessions will not be recorded even if recordings are enabled on the Configuration → Options page. This affects Screen Sharing, User Recordings for Protocol Tunnel Jump, and Shell recordings

Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.