Skip to content

Update policy

PATCH/policies/{policyId}

Endpoint API · Policy Management

Update policy. Note you can only change the settings for a base policy and roles with only assignment permissions can only change the ChangeUsersOrDevicesPolicyAppliesTo field.

Required permissionendpoint-policy:update OR endpoint-policy:assign

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
policyId path string (uuid) Yes Policy ID.

Request body

Content type: application/json

Request body fields

namestring
Policy name.
Must match the pattern ^\S(?:.*\S)?$. Must be at most 100 characters long.
priorityinteger
Policy priority.
enabledboolean
Whether the policy is turned on.
disableAtstring (date-time)
When the policy should be turned off. Set to null to remove the scheduled disable time.
appliesToobject
settingsobject
Keys have specific names documented here.

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"name\": \"Block Acme app\"
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={'name': 'Block Acme app'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "name": "Block Acme app"
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>", strings.NewReader(`{
  "name": "Block Acme app"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "name": "Block Acme app"
}),
});
const data = await response.json();
console.log(data);

Responses

200 — Updated policy.

Response fields

idstring (uuid)required
Unique API identifier for the policy.
namestringrequired
Policy name.
Must be at most 50 characters long.
typestringrequired
Policy type.
Must be one of: threat-protection, peripheral-control, application-control, web-control, agent-updating, windows-firewall, device-encryption, data-collection-and-investigation, endpoint-dns-protection, server-threat-protection, server-peripheral-control, server-application-control, server-web-control, server-lockdown, server-agent-updating, server-windows-firewall, server-file-integrity-monitoring, server-linux-runtime-detection, server-data-collection-and-investigation.
lockedByManagingAccountbooleanrequired
Whether the policy is managed by a partner or organization, 'true' mean yes.
priorityintegerrequired
Policy priority.
tenantobjectrequired
Tenant these resources belong to.
Show child attributesHide child attributes
idstring (uuid)required
namestring
enabledbooleanrequired
Whether the policy is turned on.
settingsobjectrequired
Keys have specific names documented here.
appliesToobject
disableAtstring (date-time)
When the policy should be turned off.
createdAtstring (date-time)
Time the policy was created.
createdByobject
Show child attributesHide child attributes
idstringrequired
Principal ID.
typestring (enum)required
Type of the Principal.
Must be one of: user, service.
namestring
Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
updatedAtstring (date-time)
Time the policy was last updated.
updatedByobject
Show child attributesHide child attributes
idstringrequired
Principal ID.
typestring (enum)required
Type of the Principal.
Must be one of: user, service.
namestring
Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.

Errors

Status Meaning
400 Bad request. If it is a base policy, then only settings can be updated. If the role of the caller only has assignment permissions, then only appliesTo field can be updated.
404 Can't find setting value.
409 Can't update base policies and policies locked by a managing account.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "type": "threat-protection",
  "lockedByManagingAccount": true,
  "priority": 0,
  "tenant": {
    "id": "00000000-0000-0000-0000-000000000000",
    "name": "string"
  },
  "enabled": true,
  "settings": {
    "endpoint.malware.enabled": {
      "value": true,
      "recommendedValue": true,
      "sophosManaged": true
    },
    "endpoint.scans.scheduled.days": {
      "format": "string",
      "value": [
        "monday",
        "wednesday",
        "friday"
      ]
    },
    "endpoint.scans.scheduled.hour": {
      "value": "21:00"
    },
    "endpoint.scans.scheduled.start-from": {
      "value": "2020-05-13T21:00:01.000Z",
      "format": "date-time"
    },
    "endpoint.disk-encryption.key-expiration": {
      "value": 24,
      "unit": "hours",
      "recommendedValue": 48
    }
  },
  "appliesTo": {},
  "disableAt": "2026-07-28T00:00:00Z",
  "createdAt": "2026-07-28T00:00:00Z",
  "createdBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "updatedAt": "2026-07-28T00:00:00Z",
  "updatedBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  }
}

See the guide for a narrative walkthrough of this API.