Get AAP settings¶
GET/
Endpoint API · Adaptive Attack Protection
Get Adaptive Attack Protection settings for an endpoint.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
endpointId | path | string (uuid) | Yes | Endpoint ID. |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/adaptive-attack-protection" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/adaptive-attack-protection",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/adaptive-attack-protection" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/adaptive-attack-protection", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/adaptive-attack-protection", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — Adaptive Attack Protection settings retrieved successfully.¶
Response fields
desiredStateobjectDesired status for Adaptive Attack Protection.
Show child attributesHide child attributes
enabledbooleanWhether Adaptive Attack Protection is turned on for the endpoint.
sourcestringWhether the change was made automatically by the endpoint or manually by a user in Sophos Central.
Must be one of:
Must be one of:
user, automatic.expiresAfterstringDuration (in ISO 8601 format) after which the endpoint will leave Adaptive Attack Protection. Only present if a user requested the change.
Must be at most 6 characters long.
Must be at most 6 characters long.
actualStateobjectStatus of Adaptive Attack Protection.
Show child attributesHide child attributes
enabledbooleanWhether Adaptive Attack Protection is turned on for the endpoint.
lastUpdatedAtstring (date-time)When Adaptive Attack Protection status was last updated.
expiresAtstring (date-time)When Adaptive Attack Protection will be turned off.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. |
404 | Can't find endpoint. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
See the guide for a narrative walkthrough of this API.