The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write. Collected on Windows only, it holds the machine-wide Computer Configuration settings in ComputerAdministrativeTemplates, covering areas such as BitLocker, Microsoft Defender, Remote Desktop, AutoPlay and network hardening, plus one UserAdministrativeTemplates entry per user SID with that user's User Configuration settings. Each Windows Endpoint has at most one AdministrativeTemplatesWindows, reachable from the Endpoint's administrativeTemplatesWindows field.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The AdministrativeTemplatesWindows' unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this AdministrativeTemplatesWindows was seen. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this AdministrativeTemplatesWindows belongs to if available. |
computerTemplates - ComputerAdministrativeTemplates
|
Machine-wide Administrative Templates settings from the Computer Configuration branch of Group Policy. |
userTemplates - [UserAdministrativeTemplates!]
|
Per-user Administrative Templates settings from the User Configuration branch of Group Policy, one entry per user security identifier (SID). |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
administrativeTemplatesWindowsquery: Retrieves a Windows endpoint's AdministrativeTemplatesWindows by its graph object id: the Group Policy Administrative Templates (ADMX) settings…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.AdministrativeTemplatesWindowsPayloadtype: Payload wrapper for a single AdministrativeTemplatesWindows result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "xyz789",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"computerTemplates": ComputerAdministrativeTemplates,
"userTemplates": [UserAdministrativeTemplates],
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}