Update policy¶
PATCH/
Endpoint API · Policy Management
Update policy. Note you can only change the settings for a base policy and roles with only assignment permissions can only change the ChangeUsersOrDevicesPolicyAppliesTo field.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
policyId | path | string (uuid) | Yes | Policy ID. |
Request body¶
Content type: application/json
Request body fields
namestringPolicy name.
Must match the pattern
Must match the pattern
^\S(?:.*\S)?$. Must be at most 100 characters long.priorityintegerPolicy priority.
enabledbooleanWhether the policy is turned on.
disableAtstring (date-time)When the policy should be turned off. Set to null to remove the scheduled disable time.
appliesToobjectsettingsobjectKeys have specific names documented here.
Request samples¶
curl -X PATCH "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"name\": \"Block Acme app\"
}"
import requests
response = requests.patch(
"https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={'name': 'Block Acme app'},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"name": "Block Acme app"
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>", strings.NewReader(`{
"name": "Block Acme app"
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>", {
method: "PATCH",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"name": "Block Acme app"
}),
});
const data = await response.json();
console.log(data);
Responses¶
200 — Updated policy.¶
Response fields
idstring (uuid)requiredUnique API identifier for the policy.
namestringrequiredPolicy name.
Must be at most 50 characters long.
Must be at most 50 characters long.
typestringrequiredPolicy type.
Must be one of:
Must be one of:
threat-protection, peripheral-control, application-control, web-control, agent-updating, windows-firewall, device-encryption, data-collection-and-investigation, endpoint-dns-protection, server-threat-protection, server-peripheral-control, server-application-control, server-web-control, server-lockdown, server-agent-updating, server-windows-firewall, server-file-integrity-monitoring, server-linux-runtime-detection, server-data-collection-and-investigation.lockedByManagingAccountbooleanrequiredWhether the policy is managed by a partner or organization, 'true' mean yes.
priorityintegerrequiredPolicy priority.
tenantobjectrequiredTenant these resources belong to.
Show child attributesHide child attributes
idstring (uuid)requirednamestringenabledbooleanrequiredWhether the policy is turned on.
settingsobjectrequiredKeys have specific names documented here.
appliesToobjectdisableAtstring (date-time)When the policy should be turned off.
createdAtstring (date-time)Time the policy was created.
createdByobjectShow child attributesHide child attributes
idstringrequiredPrincipal ID.
typestring (enum)requiredType of the Principal.
Must be one of:
Must be one of:
user, service.namestringPrincipal name.
accountTypestringAccount type.
Must be one of:
Must be one of:
partner, tenant, organization.accountIdstring (uuid)Account ID.
updatedAtstring (date-time)Time the policy was last updated.
updatedByobjectShow child attributesHide child attributes
idstringrequiredPrincipal ID.
typestring (enum)requiredType of the Principal.
Must be one of:
Must be one of:
user, service.namestringPrincipal name.
accountTypestringAccount type.
Must be one of:
Must be one of:
partner, tenant, organization.accountIdstring (uuid)Account ID.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. If it is a base policy, then only settings can be updated. If the role of the caller only has assignment permissions, then only appliesTo field can be updated. |
404 | Can't find setting value. |
409 | Can't update base policies and policies locked by a managing account. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"id": "00000000-0000-0000-0000-000000000000",
"name": "string",
"type": "threat-protection",
"lockedByManagingAccount": true,
"priority": 0,
"tenant": {
"id": "00000000-0000-0000-0000-000000000000",
"name": "string"
},
"enabled": true,
"settings": {
"endpoint.malware.enabled": {
"value": true,
"recommendedValue": true,
"sophosManaged": true
},
"endpoint.scans.scheduled.days": {
"format": "string",
"value": [
"monday",
"wednesday",
"friday"
]
},
"endpoint.scans.scheduled.hour": {
"value": "21:00"
},
"endpoint.scans.scheduled.start-from": {
"value": "2020-05-13T21:00:01.000Z",
"format": "date-time"
},
"endpoint.disk-encryption.key-expiration": {
"value": 24,
"unit": "hours",
"recommendedValue": 48
}
},
"appliesTo": {},
"disableAt": "2026-07-28T00:00:00Z",
"createdAt": "2026-07-28T00:00:00Z",
"createdBy": {
"id": "string",
"type": "user",
"name": "string",
"accountType": "partner",
"accountId": "00000000-0000-0000-0000-000000000000"
},
"updatedAt": "2026-07-28T00:00:00Z",
"updatedBy": {
"id": "string",
"type": "user",
"name": "string",
"accountType": "partner",
"accountId": "00000000-0000-0000-0000-000000000000"
}
}
See the guide for a narrative walkthrough of this API.