Endpoint configuration · GraphQL type

EndpointUser type

An operating system or domain user account observed on an Endpoint. The agent reads accounts through the NetUserEnum API and registry profile list on Windows, /etc/passwd and /etc/shadow on Linux, and the local Open Directory node on macOS. A user is identified on its Endpoint by its SID on Windows and by its numeric UID on Linux and macOS, so the same username on two computers yields two EndpointUser objects. Each user carries its account type (EndpointUserType), home directory, shell, and, on Linux, password-aging data (AccountSecurity); it links to its EndpointGroup memberships, the LogonSession objects that authenticated it, and its per-application settings.

Fields

Field Name Description
id - ID! The EndpointUser's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this EndpointUser was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this EndpointUser belongs to if available.
applicationInstallUserSettings - ApplicationInstallUserSettingsConnection! Per-install user settings (ApplicationInstallUserSettings) that apply to this user.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

userSystemSettings - UserSystemSettings The per-user system settings (UserSystemSettings) that apply to this user if collected.
username - String! The account's login name as reported by the operating system.
userType - EndpointUserType! Whether the account is local to the Endpoint, a domain account, or a system account. See EndpointUserType.
description - String! Description of the user if available.
homeDirectory - String! User's home directory if available.
shell - String! User's shell executable if available.
uid - Int! The operating system user identifier (UID).
sid - String The security identifier (SID) of the user, a variable-length string that uniquely identifies users or groups in the MS Windows O/S. Available on Windows endpoints only.
gid - Int The operating system group identifier (GID) of the user's primary group. Available on Linux and macOS endpoints only.
accountSecurity - AccountSecurity Account security information for this user. Available on Linux endpoints only.
homeDirectoryPermissions - String Permissions of the user's home directory formatted as a Unix mode string (e.g. "drwx------"). Available on macOS endpoints only.
duplicateUidUsernames - [String!]! The other usernames the endpoint's account database assigns this user's UID. Accounts sharing a UID are one identity to the operating system, so each can act as the others. Empty when the UID is unique. Available on Linux and macOS endpoints only. Lists at most the deployment's per-account limit, so a very large number of shared accounts shows only that many.
duplicateUidCount - Int! How many other accounts on the endpoint share this user's UID; see duplicateUidUsernames. Counts at most the deployment's per-account limit, so a very large number of shared accounts reads as that limit.
duplicateUsernameUids - [Int!]! The other UIDs the endpoint's account database gives this user's username. Empty when the username is unique. Available on Linux and macOS endpoints only. Lists at most the deployment's per-account limit, so a very large number of shared accounts shows only that many.
duplicateUsernameCount - Int! How many other accounts on the endpoint share this user's username; see duplicateUsernameUids. Counts at most the deployment's per-account limit, so a very large number of shared accounts reads as that limit.
logonSessions - LogonSessionConnection! LogonSession objects that authenticated this EndpointUser.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

groups - EndpointGroupConnection! Groups this EndpointUser is a member of.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

groupsSeen - EndpointGroupConnection! Historical sightings of this user as a member of EndpointGroup objects. Each edge records when the membership was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Restrict edges to a date/time range.

includeSeen - Boolean

Include the per-edge seen series in the response.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • endpointUser query: Retrieves an EndpointUser by its graph object id: an operating system or domain user account on an endpoint, identified by its SID on Windows or UID…

Used by

  • ApplicationInstallUserSettings type: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointGroup type: An operating system or domain group observed on an Endpoint.
  • EndpointPathEntryStats type: The stat record of one file a PathSensor discovered, stored as alternate data on the owning EndpointPath object and retrieved with…
  • LogonSession type: A user logon session observed on an Endpoint, identified by the username and the time the session started.
  • UserSystemSettings type: The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
  • EndpointUserConnection type: Collection payload for EndpointUser edges with total count.
  • EndpointUserEdge type: Edge payload for an EndpointUser with optional seen data.
  • EndpointUserPayload type: Payload wrapper for a single EndpointUser result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

Related types

  • ApplicationInstallUserSettings The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointGroup An operating system or domain group observed on an Endpoint.
  • LogonSession A user logon session observed on an Endpoint, identified by the username and the time the session started.
  • UserSystemSettings The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "applicationInstallUserSettings": ApplicationInstallUserSettingsConnection,
  "userSystemSettings": UserSystemSettings,
  "username": "xyz789",
  "userType": "LOCAL",
  "description": "abc123",
  "homeDirectory": "xyz789",
  "shell": "xyz789",
  "uid": 123,
  "sid": "xyz789",
  "gid": 123,
  "accountSecurity": AccountSecurity,
  "homeDirectoryPermissions": "xyz789",
  "duplicateUidUsernames": ["xyz789"],
  "duplicateUidCount": 123,
  "duplicateUsernameUids": [987],
  "duplicateUsernameCount": 123,
  "logonSessions": LogonSessionConnection,
  "groups": EndpointGroupConnection,
  "groupsSeen": EndpointGroupConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}