Get blocked addresses¶
GET/
Endpoint API · Blocked Addresses
Get the list of all currently blocked IP addresses and IP address ranges.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
page | query | integer | No | The page number to fetch, starting with 1. |
pageSize | query | integer | No | The size of the page requested. |
pageTotal | query | boolean | No | Whether the number of pages should be calculated and returned in the response. |
sort | query | string | No | Sort criteria for blocked communications. Valid sort fields are item, createdAt and blockedUntil. You can append ':asc' or ':desc' to one of the listed fields to specify the sort direction. The default sort is createdAt:desc.Must match the pattern (^(item|createdAt|blockedUntil)$)|(^(item|createdAt|blockedUntil):(asc|desc)$). |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-addresses", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — The list of currently blocked IP addresses and IP address ranges.¶
Response fields
itemsarray of objectrequiredBlocked IP addresses and ranges.
A blocked IP address or IP range.
Show child attributesHide child attributes
idstring (uuid)The identifier of the blocked IP address or IP range record.
itemstringA single IP address or an IP range. The IP can be IPv4 or IPv6 and the range can be specified using a dash or in CIDR format.
commentstringComment indicating why the IP address or IP range should be blocked.
Must be at most 250 characters long.
Must be at most 250 characters long.
createdAtstring (date-time)When the IP address or IP range was set to be blocked.
blockedUntilstring (date-time)The time until which the IP address or IP range will be blocked, in ISO-8601 format.
createdByobjectShow child attributesHide child attributes
idstringrequiredPrincipal Email or clientId.
typestring (enum)requiredPrincipal type.
Must be one of:
Must be one of:
user, service, system.namestringUser Principal name.
accountTypestringAccount type.
Must be one of:
Must be one of:
partner, tenant, organization.accountIdstring (uuid)Account ID.
pagesobjectrequiredShow child attributesHide child attributes
currentintegerrequiredThe 1-based page number being returned.
sizeintegerrequiredThe size of the page being returned.
totalinteger(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger(Optional) The total number of items across all pages.
maxSizeintegerrequiredThe maximum page size that can be requested.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. |
401 | Unauthorized. |
403 | Forbidden. |
404 | Can't find customer. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"items": [
{
"id": "00000000-0000-0000-0000-000000000000",
"item": "string",
"comment": "string",
"createdAt": "2026-07-28T00:00:00Z",
"blockedUntil": "2026-07-28T00:00:00Z",
"createdBy": {
"id": "string",
"type": "user",
"name": "string",
"accountType": "partner",
"accountId": "00000000-0000-0000-0000-000000000000"
}
}
],
"pages": {
"current": 0,
"size": 0,
"total": 0,
"items": 0,
"maxSize": 0
}
}
See the guide for a narrative walkthrough of this API.