Skip to content

Update isolation

PATCH/endpoints/{endpointId}/isolation

Endpoint API · Endpoint Isolation

Update isolation settings for an endpoint.

Required permissionendpoint-state:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
endpointId path string (uuid) Yes Endpoint ID.

Request body

Content type: application/json

Request body fields

enabledbooleanrequired
Whether the endpoint should be isolated or not.
commentstring
Reason endpoint should be isolated or not.
Must be at most 400 characters long.

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/isolation" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"enabled\": true,
  \"comment\": \"Isolating Foo-PC\"
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/isolation",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={'enabled': True, 'comment': 'Isolating Foo-PC'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "enabled": true,
  "comment": "Isolating Foo-PC"
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/isolation" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/isolation", strings.NewReader(`{
  "enabled": true,
  "comment": "Isolating Foo-PC"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/endpoints/<endpointId>/isolation", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "enabled": true,
  "comment": "Isolating Foo-PC"
}),
});
const data = await response.json();
console.log(data);

Responses

200 — Updated Endpoint isolation settings.

Response fields

enabledbooleanrequired
Whether the endpoint should be isolated or not.
lastEnabledAtstring (datetime)
When isolation was last enabled for the endpoint.
lastEnabledByobject
Show child attributesHide child attributes
idstringrequired
Principal Email or clientId.
typestring (enum)required
Principal type.
Must be one of: user, service, system.
namestring
User Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
lastDisabledAtstring (datetime)
When isolation was last disabled for the endpoint.
lastDisabledByobject
Show child attributesHide child attributes
idstringrequired
Principal Email or clientId.
typestring (enum)required
Principal type.
Must be one of: user, service, system.
namestring
User Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
commentstring
Reason endpoint should be isolated or not.
Must be at most 400 characters long.

Errors

Status Meaning
400 Bad request.
404 Can't find endpoint.
409 Isolation or removal from isolation in progress.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "enabled": true,
  "lastEnabledAt": "string",
  "lastEnabledBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "lastDisabledAt": "string",
  "lastDisabledBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "comment": "string"
}

See the guide for a narrative walkthrough of this API.