Endpoint configuration · GraphQL query

endpointUser query

Retrieves an EndpointUser by its graph object id: an operating system or domain user account on an endpoint, identified by its SID on Windows or UID on macOS and Linux, with its account type, home directory, group memberships, and logon sessions. An Endpoint lists its current users through users and their history through usersSeen; find them across endpoints with graphSearch on the ENDPOINT_USER object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns an EndpointUserPayload!

Arguments

Name Description
id - ID! The EndpointUser identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query endpointUser(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  endpointUser(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      applicationInstallUserSettings {
        ...ApplicationInstallUserSettingsConnectionFragment
      }
      userSystemSettings {
        ...UserSystemSettingsFragment
      }
      username
      userType
      description
      homeDirectory
      shell
      uid
      sid
      gid
      accountSecurity {
        ...AccountSecurityFragment
      }
      homeDirectoryPermissions
      duplicateUidUsernames
      duplicateUidCount
      duplicateUsernameUids
      duplicateUsernameCount
      logonSessions {
        ...LogonSessionConnectionFragment
      }
      groups {
        ...EndpointGroupConnectionFragment
      }
      groupsSeen {
        ...EndpointGroupConnectionFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"endpointUser": {"node": EndpointUser}}}