Skip to content

Get blocked addresses

GET/settings/blocked-addresses

Endpoint API · Blocked Addresses

Get the list of all currently blocked IP addresses and IP address ranges.

Required permissionblocked-ips:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
page query integer No The page number to fetch, starting with 1.
pageSize query integer No The size of the page requested.
pageTotal query boolean No Whether the number of pages should be calculated and returned in the response.
sort query string No Sort criteria for blocked communications. Valid sort fields are item, createdAt and blockedUntil. You can append ':asc' or ':desc' to one of the listed fields to specify the sort direction. The default sort is createdAt:desc.
Must match the pattern (^(item|createdAt|blockedUntil)$)|(^(item|createdAt|blockedUntil):(asc|desc)$).

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — The list of currently blocked IP addresses and IP address ranges.

Response fields

itemsarray of objectrequired
Blocked IP addresses and ranges.
A blocked IP address or IP range.
Show child attributesHide child attributes
idstring (uuid)
The identifier of the blocked IP address or IP range record.
itemstring
A single IP address or an IP range. The IP can be IPv4 or IPv6 and the range can be specified using a dash or in CIDR format.
commentstring
Comment indicating why the IP address or IP range should be blocked.
Must be at most 250 characters long.
createdAtstring (date-time)
When the IP address or IP range was set to be blocked.
blockedUntilstring (date-time)
The time until which the IP address or IP range will be blocked, in ISO-8601 format.
createdByobject
Show child attributesHide child attributes
idstringrequired
Principal Email or clientId.
typestring (enum)required
Principal type.
Must be one of: user, service, system.
namestring
User Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
pagesobjectrequired
Show child attributesHide child attributes
currentintegerrequired
The 1-based page number being returned.
sizeintegerrequired
The size of the page being returned.
totalinteger
(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger
(Optional) The total number of items across all pages.
maxSizeintegerrequired
The maximum page size that can be requested.

Errors

Status Meaning
400 Bad request.
401 Unauthorized.
403 Forbidden.
404 Can't find customer.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "item": "string",
      "comment": "string",
      "createdAt": "2026-07-28T00:00:00Z",
      "blockedUntil": "2026-07-28T00:00:00Z",
      "createdBy": {
        "id": "string",
        "type": "user",
        "name": "string",
        "accountType": "partner",
        "accountId": "00000000-0000-0000-0000-000000000000"
      }
    }
  ],
  "pages": {
    "current": 0,
    "size": 0,
    "total": 0,
    "items": 0,
    "maxSize": 0
  }
}

See the guide for a narrative walkthrough of this API.