Skip to content

Create policy

POST/policies

Mobile API · Policies

Create policy.

Required permissionmobile.policy:create

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
fields query array of string No The fields to return in a partial response.
view query string No Type of view to be returned in response.
Must be one of: basic, summary, full.

Request body

Content type: application/json

Request body fields

namestringrequired
Unique name of the policy.
Must be at most 255 characters long.
descriptionstring
A description of the policy.
Must be at most 500 characters long.
platformstring (enum)required
The device platform, i.e. the operating system.
Must be one of: iOS, macOS, android, chrome, windows.
typestringrequired
Type of the policy.
Must be at most 100 characters long.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/mobile/v1/policies" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"name\": \"My policy\",
  \"description\": \"Some description for the policy\",
  \"platform\": \"android\",
  \"type\": \"threatDefense\"
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/mobile/v1/policies",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'name': 'My policy',
    'description': 'Some description for the policy',
    'platform': 'android',
    'type': 'threatDefense'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "name": "My policy",
  "description": "Some description for the policy",
  "platform": "android",
  "type": "threatDefense"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/mobile/v1/policies" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/mobile/v1/policies", strings.NewReader(`{
  "name": "My policy",
  "description": "Some description for the policy",
  "platform": "android",
  "type": "threatDefense"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/mobile/v1/policies", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "name": "My policy",
  "description": "Some description for the policy",
  "platform": "android",
  "type": "threatDefense"
}),
});
const data = await response.json();
console.log(data);

Responses

201 — The new policy.

Response fields

idstring (uuid)required
ID of the policy.
tenantobjectrequired
Tenant this resource belongs to.
Show child attributesHide child attributes
idstring (uuid)required
namestring
namestring
Unique name of the policy.
descriptionstring
A description of the policy.
platformstring (enum)
The device platform, i.e. the operating system.
Must be one of: iOS, macOS, android, chrome, windows.
typestring
Type of the policy.
versionstring
Version of the policy.
createdByobject
Principal reference.
Show child attributesHide child attributes
idstring (uuid)
Principal ID.
typestring (enum)required
Principal type.
Must be one of: user, service, system.
accountIdstring (uuid)
Account ID.
accountTypestring (enum)
Account type.
Must be one of: partner, tenant, organization.
namestring
Principal name or email.
createdAtstring (date-time)
Indicates when the policy was created.
updatedByobject
Principal reference.
Show child attributesHide child attributes
idstring (uuid)
Principal ID.
typestring (enum)required
Principal type.
Must be one of: user, service, system.
accountIdstring (uuid)
Account ID.
accountTypestring (enum)
Account type.
Must be one of: partner, tenant, organization.
namestring
Principal name or email.
updatedAtstring (date-time)
Indicates when the policy was last updated.

Errors

Status Meaning
400 Invalid request.
401 Unauthorized.
403 Forbidden.
404 Can't find app group.
409 Conflict.
422 Maximum number of policies exceeded.
429 Too many requests. See Retry-After header.
500 Internal server error.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "id": "c9c9b03c-5cf7-4fe1-93bb-246afc9044d2",
  "tenant": {
    "id": "b8a75c7d-7492-4009-9f95-8c815551dc55",
    "name": "The name of the tenant"
  },
  "name": "My policy",
  "description": "Some description for the policy",
  "platform": "android",
  "type": "threatDefense",
  "version": 2
}

See the guide for a narrative walkthrough of this API.