The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint. Collected on macOS only, for Safari, Terminal, and Finder; the application-specific values are in settings as an ApplicationSettings union of SafariSettingsMacOS, TerminalSettingsMacOS, or FinderSettingsMacOS. Reach it from the install's userSettings field or the user's applicationInstallUserSettings field.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
Unique identifier for this graph object. |
orgId - OrganizationId!
|
Unique identifier for the owning organization. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
seen - SeenOnline!
|
When this configuration was last observed. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
applicationInstall - ApplicationInstall
|
The ApplicationInstall this setting configures. |
endpointUser - EndpointUser
|
The EndpointUser this setting applies to. |
settings - ApplicationSettings
|
The polymorphic application-specific settings (Safari, Terminal, Finder, ...). |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
applicationInstallUserSettingsquery: Retrieves an ApplicationInstallUserSettings by its graph object id: one user's settings for a supported macOS application install (Safari, Terminal,…
Used by
ApplicationInstalltype: One installed copy of an application on one Endpoint.EndpointUsertype: An operating system or domain user account observed on an Endpoint.ApplicationInstallUserSettingsConnectiontype: Collection payload for ApplicationInstallUserSettings edges with total count.ApplicationInstallUserSettingsEdgetype: Edge payload for an ApplicationInstallUserSettings.ApplicationInstallUserSettingsPayloadtype: Payload wrapper for a single ApplicationInstallUserSettings result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
Related types
ApplicationInstallOne installed copy of an application on one Endpoint.EndpointUserAn operating system or domain user account observed on an Endpoint.
Example
Example
{
"id": "4",
"orgId": "615f3b3b28284380e28a7342",
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "xyz789",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"seen": SeenOnline,
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"applicationInstall": ApplicationInstall,
"endpointUser": EndpointUser,
"settings": SafariSettingsMacOS,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}