logo
API Reference
Endpoint Group and Policy Management APIs
Initializing search
    • Get started
    • Concepts
    • APIs
    • What's New
      • Partner
      • Organization
      • Tenant
      • How our APIs work
      • Authentication
      • Regions
      • Pagination
      • Errors
      • Rate limits
      • Access tokens
      • All APIs
          • Getting started
          • Overview
            • GET Get tokens
            • POST Create token
            • PATCH Update token
            • DELETE Revoke token
          • Overview
            • GET Who am I?
          • Getting started
          • Overview
            • GET Account Health
            • GET Historical Score
            • GET Score comparisons
            • POST Snooze
          • Getting started
          • Overview
            • GET Get licenses
            • GET Get firewalls
        • Getting started
        • Overview
          • Guide — Device Software
          • Guide — Endpoint Groups Management
          • Guide — Endpoint Tags
          • Guide — Migrations
          • Guide — Packages
          • All Policy Settings
          • Policy Settings Changelog
          • Policy Settings Object Schemas
          • Application Control Categories
          • Assigned Software Packages
          • GET Get AAP settings
          • POST Update AAP settings
          • GET Get allowed items
          • POST Allow an item
          • GET Get an allowed item
          • PATCH Update allowed item
          • DELETE Delete allowed item
          • GET Get blocked addresses
          • POST Block multiple items
          • POST Unblock items
          • GET Get blocked items
          • POST Block an item
          • GET Get a blocked item
          • DELETE Delete blocked item
          • PATCH Manage device software
          • GET Download installers
          • GET Query groups
          • POST Add new group
          • GET Get groups by type
          • GET Get group
          • PATCH Update group
          • DELETE Delete group
          • GET Endpoints in group
          • POST Add to group
          • DELETE Remove from group (Endpoint Groups Management) — /endpoint-groups/{groupId}/endpoints
          • DELETE Remove from group (Endpoint Groups Management) — /endpoint-groups/{groupId}/endpoints/{endpointId}
          • POST Isolation update
          • GET Get isolation
          • PATCH Update isolation
          • POST Assign and unassign tags
          • GET Query endpoints
          • POST Delete endpoints
          • GET Get endpoint details
          • DELETE Delete endpoint
          • GET Get current settings
          • PATCH Update settings (Event Journal)
          • GET Get applications
          • POST Add application
          • GET Get application
          • PATCH Update application
          • DELETE Delete application
          • GET Get categories
          • GET Detected exploits
          • GET Detected exploit
          • POST Collect forensic log
          • GET Get status (Forensic Logs)
          • GET Globally turned on
          • GET Intrusion Prevention (Intrusion Prevention) — /settings/exclusions/intrusion-prevention
          • POST Intrusion Prevention (Intrusion Prevention) — /settings/exclusions/intrusion-prevention
          • GET Intrusion Prevention (Intrusion Prevention) — /settings/exclusions/intrusion-prevention/{exclusionId}
          • PATCH Intrusion Prevention (Intrusion Prevention) — /settings/exclusions/intrusion-prevention/{exclusionId}
          • DELETE Intrusion Prevention (Intrusion Prevention) — /settings/exclusions/intrusion-prevention/{exclusionId}
          • GET Get exclusions (Isolation Exclusions)
          • POST Isolation Exclusions
          • GET Isolation Exclusion
          • PATCH Update exclusion (Isolation Exclusions)
          • DELETE Delete exclusion (Isolation Exclusions)
          • POST Generate memory dump
          • GET Get status (Memory Dump)
          • GET Gets all migrations
          • POST Start migration job (Migrations) — /migrations
          • GET Gets a migration job
          • PUT Start migration job (Migrations) — /migrations/{migrationJobId}
          • GET Migration endpoints
          • GET Get settings (Migrations)
          • GET Get comments
          • GET Get package comment
          • PUT Update comment
          • DELETE Delete comment
          • GET Recommended packages
          • GET Get static packages
          • GET Get static package
          • POST Add special package
          • GET Get peripherals
          • GET Get a peripheral
          • GET Get policies
          • POST Create policy
          • GET Get metadata
          • GET Get policy
          • PATCH Update policy
          • DELETE Delete policy
          • POST Clone policy
          • GET Get settings (Policy Management) — /policies/{policyId}/settings
          • PATCH Update settings (Policy Management) — /policies/{policyId}/settings
          • POST Reset settings (Policy Management) — /policies/{policyId}/settings/reset
          • GET Get setting (Policy Management) — /policies/{policyId}/settings/{settingKey}
          • POST Reset setting (Policy Management) — /policies/{policyId}/settings/{settingKey}/reset
          • GET Get base
          • PATCH Update base policy
          • POST Clone base
          • GET Get settings (Policy Management) — /policies/{policyType}/base/settings
          • PATCH Update settings (Policy Management) — /policies/{policyType}/base/settings
          • POST Reset settings (Policy Management) — /policies/{policyType}/base/settings/reset
          • GET Get setting (Policy Management) — /policies/{policyType}/base/settings/{settingKey}
          • PATCH Update setting
          • POST Reset setting (Policy Management) — /policies/{policyType}/base/settings/{settingKey}/reset
          • GET Get exclusions (Scanning Exclusions)
          • POST Add exclusion
          • GET Get an exclusion
          • PATCH Update exclusion (Scanning Exclusions)
          • DELETE Delete exclusion (Scanning Exclusions)
          • POST Scan an endpoint
          • GET Get settings (Tamper Protection)
          • POST Update settings (Tamper Protection)
          • POST Check for updates
          • GET Get web categories
          • GET Get local sites
          • POST Add local site
          • GET Get a local site
          • PATCH Update a local site
          • DELETE Delete local site
          • GET Get TLS settings
          • PATCH Update TLS settings
          • GET Get excluded sites
          • PATCH Update websites
          • DELETE Delete websites
        • Getting started
        • Overview
        • Schema reference
          • GET Get alerts
          • GET Get events
        • IpsThreatData
        • AlertEntity
        • LegacyEventEntity
        • Getting started
        • Overview
        • Migrating from the Detections REST API
        • Search and filter detections
        • Resolve detections
          • QUERY alertsCountByTenant
          • QUERY alertsServiceAggregateAlertsBySeverity
          • QUERY alertsServicePoll
          • QUERY alertsServiceRetrieveAlertsByEntity
          • QUERY alertsServiceRetrieveAlertsByGroupKey
          • QUERY alertsServiceRetrieveAlertsByHost
          • QUERY alertsServiceRetrieveAlertsById
          • QUERY alertsServiceSearch
          • QUERY detectionAggregatesBySeverity
          • QUERY detectionCountByTenant
          • QUERY detectionPoll
          • QUERY detectionRetrieveByEntity
          • QUERY detectionRetrieveByGroupKey
          • QUERY detectionRetrieveByHost
          • QUERY detectionRetrieveById
          • QUERY detectionSearch
          • QUERY node
          • MUTATION alertsServiceBulkInvestigationsProcessor
          • MUTATION alertsServiceEvict (deprecated)
          • MUTATION alertsServiceUpdateInvestigationInfo
          • MUTATION alertsServiceUpdateResolutionInfo
          • MUTATION alertsServiceUpdateThreatScore
          • MUTATION alertsServiceUpdateThreatScoreV2
          • MUTATION detectionBulkInvestigationsProcessor
          • MUTATION detectionUpdateInvestigationInfo
          • MUTATION detectionUpdateResolutionInfo
          • MUTATION detectionUpdateThreatScore
          • MUTATION detectionUpdateThreatScoreV2
        • Types
        • Getting started
        • Overview
        • Migrating from the Cases REST API
        • Manage the case lifecycle
        • Search and filter cases
        • Manage case comments
        • Manage case files
        • Manage case links
          • QUERY case
          • QUERY caseComments
          • QUERY caseEvidence
          • QUERY caseFile
          • QUERY caseFiles
          • QUERY casePrimaryStatuses
          • QUERY casePrimaryVerdicts
          • QUERY caseRule
          • QUERY caseRules
          • QUERY caseSecondaryStatuses
          • QUERY caseSecondaryVerdicts
          • QUERY caseSources
          • QUERY caseTemplate
          • QUERY caseTemplates
          • QUERY caseTypes
          • QUERY cases
          • MUTATION addCaseComment
          • MUTATION addEvidenceToCase
          • MUTATION createCase
          • MUTATION createCaseLink
          • MUTATION createCaseRule
          • MUTATION createCaseTemplate
          • MUTATION deleteCaseComment
          • MUTATION deleteCaseFile
          • MUTATION deleteCaseLink
          • MUTATION deleteCaseRule
          • MUTATION deleteCaseTemplate
          • MUTATION mergeCase
          • MUTATION removeEvidenceFromCase
          • MUTATION splitCase
          • MUTATION startCaseFileUpload
          • MUTATION updateCase
          • MUTATION updateCaseComment
          • MUTATION updateCaseLink
          • MUTATION updateCaseRule
          • MUTATION updateCaseTemplate
        • Types
        • Getting started
        • Overview
          • QUERY enrichmentJobs
          • QUERY enrichmentQueries
          • QUERY lineageNodeTopRelatedEvents
          • QUERY processLineageTreeSearch
          • QUERY searchLineage
          • MUTATION enrichNode
        • Types
        • Getting started
        • Overview
        • Get event details from cases and detections
          • QUERY events
        • Types
          • Getting started
          • Fusion Query Language (QL)
          • Overview
          • Migrating from the Live Discover REST API
            • QUERY liveDiscoverCategories
            • QUERY liveDiscoverEndpointSearch
            • QUERY liveDiscoverQueries
            • QUERY liveDiscoverQuery
            • QUERY liveDiscoverQueryRun
            • QUERY liveDiscoverQueryRunEndpoints
            • QUERY liveDiscoverQueryRunResults
            • QUERY liveDiscoverQueryRunResultsCsv
            • QUERY liveDiscoverQueryRuns
            • MUTATION cancelLiveDiscoverQueryRun
            • MUTATION createLiveDiscoverCatalogCategory
            • MUTATION createLiveDiscoverQuery
            • MUTATION createLiveDiscoverSession
            • MUTATION deleteLiveDiscoverCatalogCategory
            • MUTATION deleteLiveDiscoverQuery
            • MUTATION endpointSessions
            • MUTATION runLiveDiscoverQuery
            • MUTATION updateLiveDiscoverCatalogCategory
            • MUTATION updateLiveDiscoverQuery
          • Types
          • Getting started
          • Overview
            • GET List all admins
            • POST Create new admin
            • GET Get admin by ID
            • DELETE Delete an admin
            • GET List all roles (Partner Admins)
            • POST Assign a role
            • GET Get role by ID (Partner Admins)
            • DELETE Remove a role
            • GET Get usage report
            • GET List all roles (Partner role management)
            • POST Create new role
            • GET Get permission sets
            • GET Get role by ID (Partner role management)
            • PATCH Patch role
            • DELETE Delete role by ID
            • GET Available products
            • GET Default products (Provisioning) — /provisioning/default-products
            • PATCH Default products (Provisioning) — /provisioning/default-products
            • DELETE Default products (Provisioning) — /provisioning/default-products
            • GET Enumerate tenants
            • POST Create new tenant
            • GET Get tenant details
            • PATCH Patch tenant details
            • GET Enumerate amendments
            • POST Make account changes
            • GET Get amendment by ID
            • DELETE Delete amendment
            • POST Select products
          • Getting started
          • Overview
            • GET Return partner info
            • POST Return pricing info
            • GET List quotes
            • GET Get quote
          • Overview
          • Guide
            • GET Query alerts
            • POST Query alerts (POST)
            • GET Get alert details
            • POST Act on alert
            • GET Query groups
            • POST Add new group
            • GET Get group
            • PATCH Update group
            • DELETE Delete group
            • GET Users in group
            • POST Add to group
            • DELETE Remove from group (Directory Management) — /directory/user-groups/{groupId}/users
            • DELETE Remove from group (Directory Management) — /directory/user-groups/{groupId}/users/{userId}
            • GET Query users
            • POST Add new user
            • GET Get user
            • PATCH Update user
            • DELETE Delete user
            • GET Groups of user
            • POST Add to groups
            • DELETE Remove from groups
            • DELETE Remove from group (Directory Management) — /directory/users/{userId}/groups/{groupId}
            • GET List all admins
            • POST Create new admin
            • GET Get admin by ID
            • DELETE Remove an admin
            • GET List all roles (tenant-access)
            • POST Assign a role
            • GET Get role by ID (tenant-access)
            • DELETE Remove a role
            • GET List all roles (Tenant role management)
            • POST Create new role
            • GET Get permission sets
            • GET Get role by ID (Tenant role management)
            • PATCH Patch role
            • DELETE Delete role by ID
          • Getting started
          • Overview
            • POST Add new attestation
            • GET Get attestation
          • Getting started
          • Overview
            • GET Get audit events
        • Getting started
        • Overview
          • GET List all admins
          • POST Create a new admin
          • GET Get an admin by ID
          • DELETE Remove an admin
          • GET List all roles (Organization Admins)
          • POST Assign a role
          • GET Get role by ID (Organization Admins)
          • DELETE Remove a role
          • GET List all roles (Organization role management)
          • POST Create new role
          • GET Get permission sets
          • GET Get role by ID (Organization role management)
          • PATCH Patch role
          • DELETE Delete role by ID
          • GET Enumerate tenants
          • GET Get tenant details
        • Getting started
        • Overview
          • GET Retrieve mdr-threat
          • POST Create indicators
          • DELETE Delete All IoCs
          • POST Delete indicators
          • POST Search indicators
          • PATCH Patch mdr-threat
          • GET Retrieve transaction
          • POST Import firewall configuration
          • POST Complete configuration import
          • GET Get transaction details
          • POST Export firewall configuration
          • GET Retrieve groups
          • POST Create group
          • PATCH Update group
          • DELETE Delete group
          • GET Firewalls syncStatus
          • GET List of firewalls
          • POST Upgrade firewall
          • DELETE Cancel upgrade
          • POST Check firmware
          • PATCH Update firewall
          • DELETE Delete firewall
          • POST Run action
        • Getting started
        • Overview
          • Guide — Clawback
          • Guide — Post-Delivery Quarantine
          • Guide — Quarantine
          • POST Clawback message
          • GET Message status
          • GET Query Mailboxes
          • POST Add mailbox
          • POST Add mailboxes
          • POST Delete mailboxes
          • GET Get mailbox
          • PATCH Update name
          • DELETE Delete mailbox
          • POST Change aliases
          • POST Bulk privilege
          • POST Change delegates
          • POST Change DL owners
          • GET Download job status (Post-Delivery Quarantine)
          • POST Quarantine delete (Post-Delivery Quarantine)
          • POST Quarantine release (Post-Delivery Quarantine)
          • POST Search quarantine (Post-Delivery Quarantine)
          • GET Get attachments (Post-Delivery Quarantine)
          • POST Download attachments (Post-Delivery Quarantine)
          • GET Preview message (Post-Delivery Quarantine)
          • GET Download job status (Quarantine)
          • POST Quarantine delete (Quarantine)
          • POST Quarantine release (Quarantine)
          • POST Search quarantine (Quarantine)
          • GET Get attachments (Quarantine)
          • POST Download attachments (Quarantine)
          • POST Reattach attachments
          • POST Strip attachments
          • GET Preview message (Quarantine)
          • GET Get urls
        • Getting started
        • Overview
          • GET List profiles
          • POST Create profile
          • DELETE Delete profiles
          • GET List content
          • GET Get profile
          • PUT Update profile name
          • Getting started
          • Overview
            • GET Retrieve MAC filter
            • PUT Update MAC filter
            • GET Retrieve tasks
          • Getting started
          • Overview
            • GET Retrieve MAC filter
            • PUT Update MAC filter
            • GET Retrieve tasks
          • Getting started
          • Overview
            • GET List Custom Domains
            • POST Create Custom Domain
            • GET Get Custom Domain
            • PATCH Update CDL by ID
            • DELETE Delete CDL by ID
            • GET List Locations
            • POST Create Location
            • GET Get Location
            • PATCH Update Location
            • DELETE Delete Location
            • GET List Policies
            • POST Create Policy
            • GET Get Policy
            • PATCH Update Policy
            • DELETE Delete Policy
          • Overview
            • GET Get site lists
            • POST Create a site list
            • GET Get site list
            • PUT Update site list
            • DELETE Delete site list
            • POST Clone site list
            • GET Get Sites
            • POST Add Site
            • DELETE Delete Site
            • GET Get web filtering profiles
            • POST Add a web filtering profile
            • GET Get profile metadata
            • GET Get web filtering profile
            • PUT Update web filtering profile
            • DELETE Delete web filtering profile
            • POST Clone web filtering profile
        • Getting started
        • Overview
          • GET Get list of actions
          • POST Get logs action
          • POST Locate action
          • POST Lock action
          • POST Scan action
          • POST Send Message action
          • POST Sync action
          • POST Unenroll action
          • POST Wipe action
          • GET Get action by ID
          • DELETE Delete action
          • GET List app groups
          • POST Create app group
          • GET Get app group by ID
          • PATCH Update app group
          • DELETE Delete app group
          • GET List device groups
          • POST Create device group
          • GET Device group by ID
          • PUT Update device group
          • DELETE Delete device group
          • GET Get list of devices
          • POST Create mobile device
          • GET Get by ID
          • PUT Update mobile device
          • DELETE Delete mobile device
          • GET List violations
          • GET List installed apps
          • GET Get location
          • GET List assigned policies
          • GET List device properties
          • POST Create device property
          • PUT Update property by key
          • DELETE Delete property by key
          • GET List IXM scan results
          • GET List mobile OSs
          • GET Get mobile OS by ID
          • GET List policies
          • POST Create policy
          • GET Get policy by ID
          • GET Get IXM auto-enrollment
          • POST Set up IXM auto-enrollm
          • PUT Update IXM auto-enrollm
          • DELETE Delete IXM auto-enrollm
          • GET IXM enrollment settings
          • Getting started
          • Overview
            • GET List categories
            • GET Get a category
            • GET List queries
            • GET Get a query
            • GET List query runs
            • POST Run query
            • GET Get query run
            • POST Cancel query run
            • GET Get results
          • Getting started
          • Overview
            • GET List categories
            • GET Get category
            • GET Get enrichments
            • POST Create enrichment
            • PATCH Update enrichment
            • DELETE Delete enrichment
            • GET Get queries
            • GET Get query
            • GET List query runs
            • POST Run query
            • GET Get query run
            • GET Get endpoints
            • GET Get results
          • Getting started
          • Overview
            • POST Run a groups query
            • GET Get group run
            • GET Get group results
            • POST Run detections query
            • GET Get detection counts
            • GET Get detections run
            • GET Get detection result
          • Getting started
          • Overview
            • GET Get cases
            • POST Create case
            • GET Get case by ID
            • PATCH Update a case
            • DELETE Delete a case by ID
            • GET Get case detections
            • GET Get a single detection
            • GET Get a impacted entities
            • GET Get summary of MITRE
    • What's New
    Back to index
    • Metadata
      • July 15, 2022
      • 1 min read

    Endpoint Group and Policy Management APIs

    We have updated the Endpoint v1 API with new functionality to manage groups of endpoints as well as endpoint policies. We have added two extensive guides to these new APIs:

    • Endpoint Group Management API Guide.
    • Endpoint Policy Management API Guide.

    As always, we would appreciate your feedback on the community forum here.

    Previous
    Account Management API
    Next
    Account Health Check API
    © 1997 - Sophos Ltd. All rights reserved.
    Legal Privacy Cookie Information