---
title: EndpointUser type | Wartiva GraphQL API
description: An operating system or domain user account observed on an Endpoint. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/endpoint-user.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `EndpointUser` type

An operating system or domain user account observed on an [Endpoint](https://wartiva.com/api-docs/types/endpoint.html). The agent reads accounts through the NetUserEnum API and registry profile list on Windows, `/etc/passwd` and `/etc/shadow` on Linux, and the local Open Directory node on macOS. A user is identified on its Endpoint by its SID on Windows and by its numeric UID on Linux and macOS, so the same username on two computers yields two EndpointUser objects. Each user carries its account type ([EndpointUserType](https://wartiva.com/api-docs/types/endpoint-user-type.html)), home directory, shell, and, on Linux, password-aging data ([AccountSecurity](https://wartiva.com/api-docs/types/account-security.html)); it links to its [EndpointGroup](https://wartiva.com/api-docs/types/endpoint-group.html) memberships, the [LogonSession](https://wartiva.com/api-docs/types/logon-session.html) objects that authenticated it, and its per-application settings.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The EndpointUser's unique identifier on the security graph. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | Describes when this EndpointUser was seen. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `endpoint` - [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) | The Endpoint this EndpointUser belongs to if available. |
| `applicationInstallUserSettings` - [`ApplicationInstallUserSettingsConnection!`](https://wartiva.com/api-docs/types/application-install-user-settings-connection.html) | Per-install user settings ([ApplicationInstallUserSettings](https://wartiva.com/api-docs/types/application-install-user-settings.html)) that apply to this user. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `userSystemSettings` - [`UserSystemSettings`](https://wartiva.com/api-docs/types/user-system-settings.html) | The per-user system settings ([UserSystemSettings](https://wartiva.com/api-docs/types/user-system-settings.html)) that apply to this user if collected. |
| `username` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The account's login name as reported by the operating system. |
| `userType` - [`EndpointUserType!`](https://wartiva.com/api-docs/types/endpoint-user-type.html) | Whether the account is local to the Endpoint, a domain account, or a system account. See [EndpointUserType](https://wartiva.com/api-docs/types/endpoint-user-type.html). |
| `description` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Description of the user if available. |
| `homeDirectory` - [`String!`](https://wartiva.com/api-docs/types/string.html) | User's home directory if available. |
| `shell` - [`String!`](https://wartiva.com/api-docs/types/string.html) | User's shell executable if available. |
| `uid` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The operating system user identifier (UID). |
| `sid` - [`String`](https://wartiva.com/api-docs/types/string.html) | The security identifier (SID) of the user, a variable-length string that uniquely identifies users or groups in the MS Windows O/S. Available on Windows endpoints only. |
| `gid` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The operating system group identifier (GID) of the user's primary group. Available on Linux and macOS endpoints only. |
| `accountSecurity` - [`AccountSecurity`](https://wartiva.com/api-docs/types/account-security.html) | Account security information for this user. Available on Linux endpoints only. |
| `homeDirectoryPermissions` - [`String`](https://wartiva.com/api-docs/types/string.html) | Permissions of the user's home directory formatted as a Unix mode string (e.g. "drwx------"). Available on macOS endpoints only. |
| `duplicateUidUsernames` - [`[String!]!`](https://wartiva.com/api-docs/types/string.html) | The other usernames the endpoint's account database assigns this user's UID. Accounts sharing a UID are one identity to the operating system, so each can act as the others. Empty when the UID is unique. Available on Linux and macOS endpoints only. Lists at most the deployment's per-account limit, so a very large number of shared accounts shows only that many. |
| `duplicateUidCount` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | How many other accounts on the endpoint share this user's UID; see `duplicateUidUsernames`. Counts at most the deployment's per-account limit, so a very large number of shared accounts reads as that limit. |
| `duplicateUsernameUids` - [`[Int!]!`](https://wartiva.com/api-docs/types/int.html) | The other UIDs the endpoint's account database gives this user's username. Empty when the username is unique. Available on Linux and macOS endpoints only. Lists at most the deployment's per-account limit, so a very large number of shared accounts shows only that many. |
| `duplicateUsernameCount` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | How many other accounts on the endpoint share this user's username; see `duplicateUsernameUids`. Counts at most the deployment's per-account limit, so a very large number of shared accounts reads as that limit. |
| `logonSessions` - [`LogonSessionConnection!`](https://wartiva.com/api-docs/types/logon-session-connection.html) | [LogonSession](https://wartiva.com/api-docs/types/logon-session.html) objects that authenticated this EndpointUser. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `groups` - [`EndpointGroupConnection!`](https://wartiva.com/api-docs/types/endpoint-group-connection.html) | Groups this EndpointUser is a member of. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `groupsSeen` - [`EndpointGroupConnection!`](https://wartiva.com/api-docs/types/endpoint-group-connection.html) | Historical sightings of this user as a member of [EndpointGroup](https://wartiva.com/api-docs/types/endpoint-group.html) objects. Each edge records when the membership was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. `timeRange` - [`DateTimeRangeInput`](https://wartiva.com/api-docs/types/date-time-range-input.html) Restrict edges to a date/time range. `includeSeen` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) Include the per-edge seen series in the response. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`endpointUser`](https://wartiva.com/api-docs/queries/endpoint-user.html) query: Retrieves an EndpointUser by its graph object id: an operating system or domain user account on an endpoint, identified by its SID on Windows or UID…

## Used by

- [`ApplicationInstallUserSettings`](https://wartiva.com/api-docs/types/application-install-user-settings.html) type: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointGroup`](https://wartiva.com/api-docs/types/endpoint-group.html) type: An operating system or domain group observed on an Endpoint.
- [`EndpointPathEntryStats`](https://wartiva.com/api-docs/types/endpoint-path-entry-stats.html) type: The stat record of one file a PathSensor discovered, stored as alternate data on the owning EndpointPath object and retrieved with…
- [`LogonSession`](https://wartiva.com/api-docs/types/logon-session.html) type: A user logon session observed on an Endpoint, identified by the username and the time the session started.
- [`UserSystemSettings`](https://wartiva.com/api-docs/types/user-system-settings.html) type: The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
- [`EndpointUserConnection`](https://wartiva.com/api-docs/types/endpoint-user-connection.html) type: Collection payload for EndpointUser edges with total count.
- [`EndpointUserEdge`](https://wartiva.com/api-docs/types/endpoint-user-edge.html) type: Edge payload for an EndpointUser with optional seen data.
- [`EndpointUserPayload`](https://wartiva.com/api-docs/types/endpoint-user-payload.html) type: Payload wrapper for a single EndpointUser result.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`RuleApplyToOptionKey`](https://wartiva.com/api-docs/types/rule-apply-to-option-key.html) enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

## Related types

- [`ApplicationInstallUserSettings`](https://wartiva.com/api-docs/types/application-install-user-settings.html) The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointGroup`](https://wartiva.com/api-docs/types/endpoint-group.html) An operating system or domain group observed on an Endpoint.
- [`LogonSession`](https://wartiva.com/api-docs/types/logon-session.html) A user logon session observed on an Endpoint, identified by the username and the time the session started.
- [`UserSystemSettings`](https://wartiva.com/api-docs/types/user-system-settings.html) The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.

## Example

### Example

```json
{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "applicationInstallUserSettings": ApplicationInstallUserSettingsConnection,
  "userSystemSettings": UserSystemSettings,
  "username": "xyz789",
  "userType": "LOCAL",
  "description": "abc123",
  "homeDirectory": "xyz789",
  "shell": "xyz789",
  "uid": 123,
  "sid": "xyz789",
  "gid": 123,
  "accountSecurity": AccountSecurity,
  "homeDirectoryPermissions": "xyz789",
  "duplicateUidUsernames": ["xyz789"],
  "duplicateUidCount": 123,
  "duplicateUsernameUids": [987],
  "duplicateUsernameCount": 123,
  "logonSessions": LogonSessionConnection,
  "groups": EndpointGroupConnection,
  "groupsSeen": EndpointGroupConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
