Skip to content

Get policies

GET/policies

Endpoint API · Policy Management

Get policies of a tenant.

Required permissionendpoint-policy:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
policyType query string No Policy type.
Must be one of: threat-protection, peripheral-control, application-control, data-collection-and-investigation, device-encryption, web-control, agent-updating, windows-firewall, endpoint-dns-protection, server-threat-protection, server-peripheral-control, server-application-control, server-web-control, server-lockdown, server-agent-updating, server-windows-firewall, server-file-integrity-monitoring, server-linux-runtime-detection, server-data-collection-and-investigation.
page query integer No The page number to fetch, starting with 1.
pageSize query integer No The size of the page requested.
pageTotal query boolean No Whether the number of pages should be calculated and returned in the response.
fields query array of string No The fields to return in a partial response.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/policies" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/policies",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/policies" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/policies", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/policies", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — Page of policies.

Response fields

itemsarray of objectrequired
List of policies.
Policy details.
Show child attributesHide child attributes
idstring (uuid)required
Unique API identifier for the policy.
namestringrequired
Policy name.
Must be at most 50 characters long.
typestringrequired
Policy type.
Must be one of: threat-protection, peripheral-control, application-control, web-control, agent-updating, windows-firewall, device-encryption, data-collection-and-investigation, endpoint-dns-protection, server-threat-protection, server-peripheral-control, server-application-control, server-web-control, server-lockdown, server-agent-updating, server-windows-firewall, server-file-integrity-monitoring, server-linux-runtime-detection, server-data-collection-and-investigation.
lockedByManagingAccountbooleanrequired
Whether the policy is managed by a partner or organization, 'true' mean yes.
priorityintegerrequired
Policy priority.
tenantobjectrequired
Tenant these resources belong to.
Show child attributesHide child attributes
idstring (uuid)required
namestring
enabledbooleanrequired
Whether the policy is turned on.
settingsobjectrequired
Keys have specific names documented here.
appliesToobject
disableAtstring (date-time)
When the policy should be turned off.
createdAtstring (date-time)
Time the policy was created.
createdByobject
Show child attributesHide child attributes
idstringrequired
Principal ID.
typestring (enum)required
Type of the Principal.
Must be one of: user, service.
namestring
Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
updatedAtstring (date-time)
Time the policy was last updated.
updatedByobject
Show child attributesHide child attributes
idstringrequired
Principal ID.
typestring (enum)required
Type of the Principal.
Must be one of: user, service.
namestring
Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
pagesobjectrequired
Show child attributesHide child attributes
currentintegerrequired
The 1-based page number being returned.
sizeintegerrequired
The size of the page being returned.
totalinteger
(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger
(Optional) The total number of items across all pages.
maxSizeintegerrequired
The maximum page size that can be requested.

Errors

Status Meaning
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string",
      "type": "threat-protection",
      "lockedByManagingAccount": true,
      "priority": 0,
      "tenant": {
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "string"
      },
      "enabled": true,
      "settings": {
        "endpoint.malware.enabled": {
          "value": true,
          "recommendedValue": true,
          "sophosManaged": true
        },
        "endpoint.scans.scheduled.days": {
          "format": "string",
          "value": [
            "monday",
            "wednesday",
            "friday"
          ]
        },
        "endpoint.scans.scheduled.hour": {
          "value": "21:00"
        },
        "endpoint.scans.scheduled.start-from": {
          "value": "2020-05-13T21:00:01.000Z",
          "format": "date-time"
        },
        "endpoint.disk-encryption.key-expiration": {
          "value": 24,
          "unit": "hours",
          "recommendedValue": 48
        }
      },
      "appliesTo": {},
      "disableAt": "2026-07-28T00:00:00Z",
      "createdAt": "2026-07-28T00:00:00Z",
      "createdBy": {
        "id": "string",
        "type": "user",
        "name": "string",
        "accountType": "partner",
        "accountId": "00000000-0000-0000-0000-000000000000"
      },
      "updatedAt": "2026-07-28T00:00:00Z",
      "updatedBy": {
        "id": "string",
        "type": "user",
        "name": "string",
        "accountType": "partner",
        "accountId": "00000000-0000-0000-0000-000000000000"
      }
    }
  ],
  "pages": {
    "current": 0,
    "size": 0,
    "total": 0,
    "items": 0,
    "maxSize": 0
  }
}

See the guide for a narrative walkthrough of this API.