Retrieves an EndpointUser by its graph object id: an operating system or domain user account on an endpoint, identified by its SID on Windows or UID on macOS and Linux, with its account type, home directory, group memberships, and logon sessions. An Endpoint lists its current users through users and their history through usersSeen; find them across endpoints with graphSearch on the ENDPOINT_USER object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an EndpointUserPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The EndpointUser identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query endpointUser(
$id: ID!,
$mockOptions: MockDataInput
) {
endpointUser(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
applicationInstallUserSettings {
...ApplicationInstallUserSettingsConnectionFragment
}
userSystemSettings {
...UserSystemSettingsFragment
}
username
userType
description
homeDirectory
shell
uid
sid
gid
accountSecurity {
...AccountSecurityFragment
}
homeDirectoryPermissions
duplicateUidUsernames
duplicateUidCount
duplicateUsernameUids
duplicateUsernameCount
logonSessions {
...LogonSessionConnectionFragment
}
groups {
...EndpointGroupConnectionFragment
}
groupsSeen {
...EndpointGroupConnectionFragment
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"endpointUser": {"node": EndpointUser}}}