Skip to content

Update settings

PATCH/policies/{policyId}/settings

Endpoint API · Policy Management

Update policy settings.

Required permissionendpoint-policy:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
policyId path string (uuid) Yes Policy ID.

Request body

Content type: application/json

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>/settings" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"endpoint.device-encryption.encrypt-non-boot-volumes\": {
    \"value\": true
  },
  \"endpoint.device-encryption.require-startup-authentication\": {
    \"value\": false
  }
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>/settings",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'endpoint.device-encryption.encrypt-non-boot-volumes': {'value': True},
    'endpoint.device-encryption.require-startup-authentication': {   'value': False}},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "endpoint.device-encryption.encrypt-non-boot-volumes": {
    "value": true
  },
  "endpoint.device-encryption.require-startup-authentication": {
    "value": false
  }
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>/settings" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>/settings", strings.NewReader(`{
  "endpoint.device-encryption.encrypt-non-boot-volumes": {
    "value": true
  },
  "endpoint.device-encryption.require-startup-authentication": {
    "value": false
  }
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/policies/<policyId>/settings", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "endpoint.device-encryption.encrypt-non-boot-volumes": {
    "value": true
  },
  "endpoint.device-encryption.require-startup-authentication": {
    "value": false
  }
}),
});
const data = await response.json();
console.log(data);

Responses

200 — Updated settings.

Errors

Status Meaning
404 Can't find setting value.
409 Can't update base policies and policies locked by a managing account.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "endpoint.malware.enabled": {
    "value": true,
    "recommendedValue": true,
    "sophosManaged": true
  },
  "endpoint.scans.scheduled.days": {
    "format": "string",
    "value": [
      "monday",
      "wednesday",
      "friday"
    ]
  },
  "endpoint.scans.scheduled.hour": {
    "value": "21:00"
  },
  "endpoint.scans.scheduled.start-from": {
    "value": "2020-05-13T21:00:01.000Z",
    "format": "date-time"
  },
  "endpoint.disk-encryption.key-expiration": {
    "value": 24,
    "unit": "hours",
    "recommendedValue": 48
  }
}

See the guide for a narrative walkthrough of this API.