Skip to content

Latest commit

 

History

History
191 lines (150 loc) · 6.49 KB

File metadata and controls

191 lines (150 loc) · 6.49 KB
title List healthIssues
description Get a list of health issue objects and their properties.
author amirfeldman
ms.localizationpriority medium
doc_type apiPageType
ms.subservice security
ms.date 09/12/2024

List healthIssues

Namespace: microsoft.graph.security

[!INCLUDE beta-disclaimer]

Get a list of health issue objects and their properties.

[!INCLUDE national-cloud-support]

Permissions

Choose the permission or permissions marked as least privileged for this API. Use a higher privileged permission or permissions only if your app requires it. For details about delegated and application permissions, see Permission types. To learn more about these permissions, see the permissions reference.

[!INCLUDE permissions-table]

HTTP request

GET /security/identities/healthIssues

Optional query parameters

This method supports the $count, $filter, $skip, $top, and $select OData query parameters to help customize the response. For general information, see OData query parameters.

The following examples show how to use optional query parameters.

Get all open health alerts

GET /security/identities/healthIssues?$filter=Status eq 'open'

Get the top five open health alerts

GET /security/identities/healthIssues?$filter=Status eq 'open'&$top=5

Get open health alerts based on issue type

GET /security/identities/healthIssues?$filter=Status eq 'open' and healthIssueType eq 'global'
GET /security/identities/healthIssues?$filter=Status eq 'open' and healthIssueType eq 'sensor'

Get open health alerts based on severity

GET /security/identities/healthIssues?$filter=Status eq 'open' and severity eq 'medium'
GET /security/identities/healthIssues?$filter=Status eq 'open' and severity eq 'low'

Get open global health alerts where the domain name or sensor DNS name ends with a specific value

The following example shows how to get global health alerts where the domain name or sensor DNS name ends with a specific value, for example, contoso.com.

GET /security/identities/healthissues?$filter=Status eq 'open' and healthIssueType eq 'global' and domainNames/any(s:endswith(s,'contoso.com'))
GET /security/identities/healthissues?$filter=Status eq 'open' and healthIssueType eq 'global' and sensorDNSNames/any(s:endswith(s,'contoso.com'))

Request headers

Name Description
Authorization Bearer {token}. Required. Learn more about authentication and authorization.

Request body

Don't supply a request body for this method.

Response

If successful, this method returns a 200 OK response code and a collection of microsoft.graph.security.healthIssue objects in the response body.

Examples

Request

The following example shows a request.

GET https://graph.microsoft.com/beta/security/identities/healthIssues

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]

[!INCLUDE sample-code] [!INCLUDE sdk-documentation]


Response

The following example shows the response.

Note: The response object shown here might be shortened for readability.

HTTP/1.1 200 OK
Content-Type: application/json

{
  "value": [
    {
      "@odata.type": "#microsoft.graph.security.healthIssue",
      "additionalInformation": ["Descendant User Objects (Schema-Id-Guid: bf967aba-0de6-11d0-a285-00aa003049e2)"],
      "createdDateTime": "2022-07-15T12:19:27.7211305Z",
      "description": "Directory Services Object Auditing isn't configured as required on domain1.contoso.com",
      "displayName": "Directory Services Object Auditing isn't configured as required",
      "domainNames": ["domain1.contoso.com", "domain2.contoso.com"],
      "healthIssueType": "Global",
      "id": "b3c1b5fc-828c-45fa-a1e1-10d74f6d6e9c",
      "issueTypeId": "1031",
      "lastModifiedDateTime": "2022-07-15T12:19:27.7211305Z",
      "recommendations": ["Please configure the Directory Services Object Auditing events according to the guidance as described in https://aka.ms/mdi/objectauditing"],
      "recommendedActionCommands": ["Import-Module DefenderForIdentity"],
      "sensorDNSNames": ["DC1.domain1.contoso.com", "DC2.domain2.contoso.com"],
      "severity": "medium",
      "status": "open"
    }
  ]
}