This article will encompass all portalAPI calls that are related to /portalAPI/Computer/* endpoints
If you are new to working with ThreatLocker PortalAPI endpoints and/or have questions regarding authentication and terminology used throughout this article, please look through the following guide:
When setting permissions for your API user, additional Maintenance Mode permissioning may be required in addition to the permissions needed to call each API. See the KB article below for more permissions relating to the enabling and disabling of Maintenance Modes.
Note: Proxy/Relay configuration fields have been omitted from this documentation as these settings are now configured using Advanced Settings. If you are using a Proxy/Relay and your ThreatLocker Windows agent version is 10.3.1 or greater, or your Linux agent version is 2.3 or greater, configure the corresponding Advanced Setting before calling any API endpoint that makes changes to your computers. When calling APIs that previously set/modified the Proxy/Relay settings, the previously configured settings will be removed.
ComputerGetByAllParameters
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerGetByAllParameters
- Method: POST
- Description: This API is used when navigating to the Assets icon and selecting the Computers page from the pop-out menu in the ThreatLocker Portal. This API is also used when selecting the Computers tab when in another portion of the Assets section of the Portal. This API returns all your computers based on the fields you select. Ensure that the header you use matches the location where you want to view your computers.
- Required Body/Parameters
- Fields
- orderBy: This field determines the order in which the computers will be returned, based on the isAscending field and the text entered below. This field expects one of the following options from the Entry to API column in the table below to be entered:
- Fields
Portal Display Name |
Entry to API |
| Name / Operating System | "computername" |
| Group | "group" |
| Mode | "action" |
| Last Check-in | "lastcheckin" |
| Install Date | "computerinstalldate" |
| Denied Count | "deniedcountthreedays" |
| Agent Version | "threatlockerversion" |
-
-
- pageNumber and pageSize: These fields determine how many computers will be returned, as if the response were on the Devices page. However, these fields do not follow the same conventions for pageNumber and pageSize as the Portal does (the Portal uses 25, 50, 100, or 500 for pageSize). Any valid integer can be entered, and it will be returned in the selected format. For instance, if there are 5 computers to be returned but "pageNumber": 1 and "pageSize": 2, 2 entries will be returned per page, and the first two computers will be returned.
- pageNumber and pageSize: These fields determine how many computers will be returned, as if the response were on the Devices page. However, these fields do not follow the same conventions for pageNumber and pageSize as the Portal does (the Portal uses 25, 50, 100, or 500 for pageSize). Any valid integer can be entered, and it will be returned in the selected format. For instance, if there are 5 computers to be returned but "pageNumber": 1 and "pageSize": 2, 2 entries will be returned per page, and the first two computers will be returned.
-
Required body
{
"orderBy": "<String>",
"pageNumber": <Integer>,
"pageSize": <Integer>
}
- Optional Body/Parameters
- Fields
-
action: This field determines which computers will be returned based on one or multiple fields. When this field is omitted, all computers will be returned based on the other fields used. Review the table found in the kindOfAction field description below to determine the action fields that can be used.
- advancedSearchParameters: This field determines the Advanced Search filters applied to the computers that will be returned. When this field is omitted, all computers will be returned based on the other fields used. One or multiple filters can be added. As demonstrated in the Optional body section, each filter requires each of the fields listed below:
- searchValue: This field determines the search value that will be applied to the Advanced Search filter. This field expects valid input based on the selected filter type. For example, when using the "Machine State" filter type, any valid machine state ("Active", "Offline", or "Inactive") is expected. When using the OS filter, enter the full OS name as it appears in the ThreatLocker Portal; for example, "Windows Server 2016 Datacenter".
-
- Expects: Any text input corresponding to the filter type selected
-
- Expects: true or false
- computerGroup: This field determines which computer group's computers will be returned when a valid computerGroupId is entered into this field. When this field is omitted or set to "00000000-0000-0000-0000-000000000000" or "", all computers will be returned based on the other fields used. To get a list of computerGroupIds, use the ComputerGroupGetByParameters API.
-
isAscending: This field determines the order in which computers will be returned. When this field is omitted or set to true, the computers will be returned in decreasing order, from high to low (alphabetically/numerically), based on the orderBy field used. When this field is set to false, the computers will be returned in increasing order, from low to high, based on the orderBy field used.
- kindOfAction: This field determines the filters applied when the computers are returned. When this field is omitted, all computers will be returned based on the other fields used. When using the "AgentVersion" option, the threatlockerVersion field below must be used. This field expects the corresponding entry into this field and the action field in order to return results based on the filters:
-
- Fields
Portal Display Name |
Entry to kindOfAction |
Entry to action |
| Computer Mode | "Computer Mode" | One of the options listed below in the Computer Mode dropdown |
| Disable Tamper Protection | "TamperProtectionDisabled" | "TamperProtectionDisabled" |
| Needs Review | "NeedsReview" | "NeedsReview" |
| Ready to Secure | "ReadyToSecure" | "ReadyToSecure" |
| Waiting for Baseline | "BaselineNotUploaded" | "BaselineNotUploaded" |
| Update Channel | "Update Channel" | One of the options listed below in the Update Channel dropdown |
| Agent Version | "AgentVersion" | "AgentVersion" |
| Machine State | "Machine State" | One of the options listed below in the Machine State dropdown |
Computer Mode
Portal Display Name |
Entry to API |
| All Computer Modes | "" |
| Secured | "Secure" |
| Application Control Installation Mode | "Installation" |
| Application Control Learning Mode | "Learning" |
| Application Control Monitor Only | "Monitor Only" |
| Elevation Mode | "Elevation Mode" |
Update Channel
Portal Display Name |
Entry to API |
| Manual Update | "Manual Update" |
| Pre-Releases | "Pre-Releases" |
| Regular | "Regular" |
| Expedited | "Expedited" |
| Slow and Steady | "Slow and Steady" |
Machine State
Portal Display Name |
Entry to API |
| Active | "Active" |
| Offline | "Offline" |
| Inactive | "Inactive" |
-
-
-
searchBy: This field determines how the text entered into the searchText field will be searched. When this field is omitted and the searchText field is used, the computers will be searched on their "Computer and Asset Name". When this field is omitted and searchText is not used, all computers will be returned based on the other fields used. This field expects the Integer associated with what you would like to search by to be entered:
- searchText: This field allows you to search/narrow the computers returned by inputting any text/details you want to search for. This field searches based on the searchBy field selected and what is entered into this field. When this field is omitted, all computers will be displayed based on the other fields used. This field searches case-insensitively and effectively uses wildcards on either side of the entered text. For example, entering "Work" into this field, with the searchBy field set to 3, will return any computer in a group whose group name contains "Work".
-
threatlockerVersion: This field determines which computers will be returned based on their ThreatLocker Agent version. When this field is omitted, all computers with any version of ThreatLocker will be returned based on the other fields used. This field searches based on the ThreatLocker Version actively installed on the computer, not the target version/the version it will update to. This field expects the text of the ThreatLocker Version. Example: "10.12.10"
-
-
Optional body
- Permission Requirements
- Assign any one of the following permissions:
- Edit Computers
- Install Computers
- View Computers
-
View Computers - Managed Organization Only
- Assign any one of the following permissions:
ComputerGetForEditById
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerGetForEditById
- Method: GET
- Description: This API is used on the Devices page in the ThreatLocker Portal when clicking on an individual computer and opening the computer sidebar to view its information. This API gets all the computer details for an individually selected computer. If looking to view a computer that is in a different organization than the currently logged-in/managed organization, utilize the managedOrganizationId header.
- Required Body/Parameters
- computerId: This field is used to determine what computer's details will be returned.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field is used to determine what computer's details will be returned.
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- View Computers
ComputerUpdateForEdit
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateForEdit
- Method: PATCH
- Description: This API is used when navigating to the Assets icon and selecting the Computers page from the pop-out menu in the ThreatLocker Portal, locating and selecting the computer you wish to change, making your changes, and selecting "Save". This API updates computers in your organization. Ensure that the managedOrganizationId header you use matches the location where the computer exists.
Note: Be sure to review all sections below and check the current configuration of the computer you are making changes to. You may unintentionally make changes to your computer if fields are changed/omitted.
- Required Body/Parameters
- Fields
-
computerId: This field determines which computer will be updated. The computerId must match the computer's existing value; it cannot be changed after creation.
-
computerGroupId: This field determines the computer group where the computer exists. This field can also be used to move the computer into a different computer group. If you want to move the computer into a new group, enter the destination computerGroupId in this field. Otherwise, enter the existing computerGroupId into this field. It is recommended that, after the computer checks into its new computer group, policies be deployed either using the "Deploy Policies" button in the top-right corner of the Portal or through the API, documentation linked below.
-
- Fields
/portalAPI/DeployPolicyQueue/* | ThreatLocker Help Center
-
-
-
- Expects a GUID in format: "00000000-0000-0000-0000-000000000000"
- name: This field determines the name that will be applied to the computer. Any name can be entered. If you do not wish to change the computer's name, enter the existing name.
-
-
Required body
- Optional Body/Parameters
- Fields
-
aliases: This field determines whether aliases will be applied to the computer. When this field is omitted, no aliases will be applied. One or multiple aliases can be entered into this field. Aliases specify a name other than the FQDN and DN that can be used for device-to-device communications through ZTNA. The Optional body section below demonstrates how to add three aliases. If an alias is already applied to the computer, it must be re-entered to keep it applied.
-
- Fields
Note: The options applied to the computer in the options field below should be used with extreme care as changing these options may greatly impact ThreatLocker's ability to monitor and secure your environment.
Options Tab: Choices and Descriptions | ThreatLocker Help Center
-
-
-
options: This field determines which options will apply to the computer. When this field is omitted, no options will be applied. One or multiple options can be entered into this field. For each option, enter the text of the option exactly as it appears in the KB article above. The Optional body section below demonstrates how to add four options. If an option is already applied to the computer, it must be re-entered to keep it applied.
-
-
Optional body
- Permission Requirements
- Assign this permission:
- Edit Computers
- Assign this permission:
ComputerUpdateBaselineRescan
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateBaselineRescan
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting the checkbox next to one or multiple computers and then clicking the "Rescan Baseline" button. This API will restart the Baseline for selected/supplied computers, completing a Baseline rescan on the computer. This can be used to restart the Baseline on multiple computers at the same time like you can in the Portal.
- Required Body/Parameters
- Fields
- computerId: This field is used to determine which computer will have the Baseline rescan complete.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- organizationId: This field is used to specify the organization where the computer exists that will have the Baseline rescan complete.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerGroupId: This field is used to specify the computer group where the computer exists that will have the Baseline rescan complete.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- enableLearning: This field is used to determine whether Learning will be enabled based on the computer group settings. Re-enabling Learning is not mandatory, but is typically recommended when completing a rescan. If you do not wish to enable Learning on the endpoint, set this field to false.
- Expects: true or false
- computerId: This field is used to determine which computer will have the Baseline rescan complete.
- Required/Example body
- The body below, when filled in with corresponding id values, will complete a Baseline rescan on two computers. It is important to fill out all 3 fields (computerId, organizationId, and computerGroupId) for each computer you would like to rescan the Baseline on.
- Fields
{
"computerDetailDtos":
[
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000",
"computerGroupId": "00000000-0000-0000-0000-000000000000"
},
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000",
"computerGroupId": "00000000-0000-0000-0000-000000000000"
}
],
"enableLearning": <Boolean>
}
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerUpdateShouldRestartByIds
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateShouldRestartByIds
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting the checkbox next to one or multiple computers and then clicking the "Restart Agent(s)" button. This API will restart the service for the selected computers. This can be used to restart the ThreatLocker Service on multiple computers at the same time like in the ThreatLocker Portal.
- Required Body/Parameters
- Fields
- computerId: This field is used to determine which computer will complete the ThreatLocker Service restart.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- organizationId: This field is used to specify the organization where the computer exists that will have the ThreatLocker Service restarted.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field is used to determine which computer will complete the ThreatLocker Service restart.
- Required body
- The body below, when filled in with corresponding id values, will complete a service restart on two computers. It is important to fill out both fields (computerId and organizationId) for each computer you would like to restart the ThreatLocker Service on.
- Fields
[
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000"
},
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000"
}
]
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerUpdateShouldRestartByOrganization
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateShouldRestartByOrganization
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting from the "Computer Options" hamburger dropdown next to "Install Computer" and clicking the "Restart Agent (ALL)" button. This API will restart the service on all computers in the organization as per the field passed in below. If looking to restart the ThreatLocker Service for all computers only in a different organization than the currently logged in/managed organization, utilize the managedOrganizationId header.
- Required Body/Parameters
- This expects either true or false (with no backets or braces, just the word) to be entered to determine whether the service restart will apply to child organizations or not. If wanting the service restart to apply to child organizations as well, set this field to true. Otherwise, set this to false and the service restart will only apply to the currently managed organization.
- Expects: true or false
- This expects either true or false (with no backets or braces, just the word) to be entered to determine whether the service restart will apply to child organizations or not. If wanting the service restart to apply to child organizations as well, set this field to true. Otherwise, set this to false and the service restart will only apply to the currently managed organization.
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerMoveToOtherOrganization
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerMoveToOtherOrganization
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting the checkbox next to one or multiple computers, clicking the "Move Computer" button, entering the target organization and computer group, selecting whether to enable Learning and rescan Baseline or not, and then clicking "Move Computer" where this API is called and the computer is moved. This API will move a computer(s) into another organization.
- Required Body/Parameters
- Fields
- computerGroupId: This field is used to specify the current computer group where the computer that will be moved exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field is used to determine which computer will be moved to a different group and/or organization.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerName: This field is required for processing, but is ok to leave blank. Anything input will not effect/make changes to the computer moved by this API.
- Expects: ""
- group: This field is required for processing, but is ok to leave blank. Anything input will not effect/make changes to the computer moved by this API.
- Expects: ""
- hostname: This field is required for processing, but is ok to leave blank. Anything input will not effect/make changes to the computer moved by this API.
- Expects: ""
- maintenanceTypeId: This field expects any Integer to be entered for processing. This will not change the Maintenance Mode on the machine, however something must be entered. The computer will either maintain the existing Maintenance Mode and end date and time or enable Learning and rescan Baseline based upon the Computer Group -> Learning Mode settings.
- Expects: An Integer value
- operatingSystem: This field is required for processing, but is ok to leave blank. Anything input will not effect/make changes to the computer moved by this API.
- Expects: ""
- organization: This field is required for processing, but is ok to leave blank. Anything input will not effect/make changes to the computer moved by this API.
- Expects: ""
- organizationId: This field is used to specify the current organization where the computer that will be moved exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- osType: This field is used to specify the osType of the computer being moved and expects one of the following Integer values to be entered that correspond to the computer:
- Windows = 1
- MAC = 2
- Linux = 3
- Windows XP = 5
- enableLearningRescan: This field is used to specify whether Learning will be enabled as per the computer group settings and if the Baseline will be rescanned or not. Set this to true to enable Learning and to rescan the Baseline on the computer. Set this to false to just move the computer with no changes to the Maintenance Mode(s) active on the computer and Baseline.
- Expects: true or false
- targetComputerGroupId: This field is used to specify the new computer group that the computer(s) entered will be moved into.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- targetOrganizationId: This field is used to specify the new or current (if just moving computer groups within the same org) organization that the computer(s) entered will be moved into.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerGroupId: This field is used to specify the current computer group where the computer that will be moved exists.
- Required body
- The body below, when filled in with the corresponding values for each field, will move two computers. It is important to fill out all the fields for each computer you would like to move.
- Fields
{
"computerDetailDtos": [
{
"computerGroupId": "00000000-0000-0000-0000-000000000000",
"computerId": "00000000-0000-0000-0000-000000000000",
"computerName": "<String>",
"group": "<String>",
"hostname": "<String>",
"maintenanceTypeId": <Integer>,
"operatingSystem": "<String>",
"organization": "<String>",
"organizationId": "00000000-0000-0000-0000-000000000000",
"osType": <Integer>
},
{
"computerGroupId": "00000000-0000-0000-0000-000000000000 ",
"computerId": "00000000-0000-0000-0000-000000000000 ",
"computerName": "<String>",
"group": "<String>",
"hostname": "<String>",
"maintenanceTypeId": <Integer>,
"operatingSystem": "<String>",
"organization": "<String>",
"organizationId": "00000000-0000-0000-0000-000000000000 ",
"osType": <Integer>
}
],
"enableLearningRescan": <Boolean>,
"targetComputerGroupId": "00000000-0000-0000-0000-000000000000",
"targetOrganizationId": "00000000-0000-0000-0000-000000000000"
}
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerEnableProtection
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerEnableProtection
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting the checkbox next to one or multiple computers that are in an insecure state, clicking the "Secure Mode" button, and clicking "Yes" in the confirmation text box that appears. This API will enable Secured Mode on the selected/supplied computer(s).
- Required Body/Parameters
- Fields
- computerId: This field is used to determine which computer will have Secured Mode enabled.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- organizationId: This field is used to specify the organization where the computer that will have Secured Mode enabled exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field is used to determine which computer will have Secured Mode enabled.
- Required body
- The body below, when filled in with corresponding id values, will enable Secured Mode on two computers. It is important to fill out both fields (computerId and organizationId) for each computer you would like to enable Secured Mode on.
- Fields
{
"computerDetailDtos":
[
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000"
},
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000"
}
]
}
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerDisableProtection
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerDisableProtection
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting the checkbox next to one or multiple computers that you want to enable a Maintenance Mode on (disable protection), clicking the "Schedule Maintenance" button, selecting the start date and time plus end date and time, selecting the Maintenance Mode that will be enabled, determining whether the end user on the computer has the option to end the Maintenance Mode directly from the tray popup on their computer or not, and clicking "Start Maintenance" where this endpoint is called. This API will disable protection on a computer(s) as per the other fields passed in.
- Required Body/Parameters
- Fields
- computerGroupId: This field is used to specify the computer group where the computer that will have the Maintenance Mode enabled exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field is used to determine which computer will have the Maintenance Mode enabled.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- organizationId: This field is used to specify the organization where the computer that will have the Maintenance Mode enabled exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- endDate: This field specifies when the Maintenance Mode will end on a computer. This expects a time entered in UTC in format "YYYY-MM-DDTHH:MM:SSZ", where YYYY is the year, the first MM is the month, DD is the day, HH are the hours, the second MM are the minutes, and SS are the seconds. The T must be included to designate the time and should not be changed or removed.
- Expects end date and time in format: "YYYY-MM-DDTHH:MM:SSZ"
- startDate: This field specifies when the Maintenance Mode will start on a computer. This expects a time entered in UTC in format "YYYY-MM-DDTHH:MM:SSZ", where YYYY is the year, the first MM is the month, DD is the day, HH are the hours, the second MM are the minutes, and SS are the seconds. The T must be included to designate the time and should not be changed or removed.
- Expects start date and time in format: "YYYY-MM-DDTHH:MM:SSZ"
- maintenanceModeType: This field specifies the Maintenance Mode that will be enabled on the computer. Listed below are the Integer ids that are expected to be entered to have the corresponding Maintenance Mode enabled.
- Application Control Monitor Only = 1
- Application Control Learning Mode = 3
- When using this Maintenance Mode, refer to the applicationId field below for how to enable this Maintenance Mode successfully.
- Disable Tamper Protection = 6
- permitEnd: This field is used to determine whether the end user has the option to end the Maintenance Mode directly from their computer. If permitEnd is set to true, the tray prompt will appear in the bottom right corner of their screen so the user can end the Maintenance Mode directly from their computer. If permitEnd is set to false, there will be nothing that appears for the end user.
- Expects: true or false
- applicationId: This field is used when enabling Learning Mode through this endpoint to allow you to specify whether automatic computer or automatic group Learning will be enabled. Automatic computer Learning ("autocomp") will automatically create applications and apply new policies at the computer level and automatic group Learning (“autogroup”) will automatically create applications and apply new policies at the group level. Using one of these options is required to enable Learning mode with this API.
- Expects: autocomp or autogroup
- computerGroupId: This field is used to specify the computer group where the computer that will have the Maintenance Mode enabled exists.
- Required body
- The body below, when filled in with corresponding values for each field, will enable the desired Maintenance Mode on two computers. It is important to fill out all the fields for each computer on which you would like to enable the Maintenance Mode.
- Fields
{
"computerDetailDtos":
[
{
"computerGroupId": "00000000-0000-0000-0000-000000000000",
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000"
},
{
"computerGroupId": "00000000-0000-0000-0000-000000000000",
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000"
}
]
"endDate": "YYYY-MM-DDTHH:MM:SSZ",
"startDate": "YYYY-MM-DDTHH:MM:SSZ",
"maintenanceModeType": <Integer>,
"permitEnd": <Boolean>,
"applicationId": "<String>"
}
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerRemoveDuplicate
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerRemoveDuplicate
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting from the "Computer Options" hamburger dropdown next to "Install Computer" and clicking the "Remove Duplicate Computers" button. This API will remove duplicate computers from the Devices page based on install date and the last check-in date and time of each computer with the same hostname. Only computers that have not been active in the ThreatLocker Portal at the same time will be removed. More information about removing computers can be found in the KB article below:
Remove Duplicate Computers Button | ThreatLocker Help Center
If looking to remove duplicate computers for all computers only in a different organization than the currently logged in/managed organization, utilize the managedOrganizationId header
- Required Body/Parameters
- This expects either true or false (with no backets or braces, just the word) to be entered to determine whether to remove duplicate computers from child organizations or not. If wanting to remove duplicate computers from child organizations as well, set this field to true. Otherwise, set this to false and the duplicate computers will only be removed from the currently managed organization.
- Expects: true or false
- This expects either true or false (with no backets or braces, just the word) to be entered to determine whether to remove duplicate computers from child organizations or not. If wanting to remove duplicate computers from child organizations as well, set this field to true. Otherwise, set this to false and the duplicate computers will only be removed from the currently managed organization.
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerUpdateMaintenanceMode
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateMaintenanceMode
- Method: POST
- Description: This API is used when navigating to the Assets icon and selecting the Computers page from the popout menu in the ThreatLocker Portal, and selecting a Maintenance Mode from the dropdown in the Mode column. This API is also used when selecting an icon in the Mode column and enabling one of the Maintenance Modes in the pop-up menu. This API updates the Maintenance Mode on an individual computer.
- Required Body/Parameters
- Fields
- applicationId: This field is used when enabling either the Installation Legacy or Application Control Learning Mode Maintenance Mode on a computer. With Installation Legacy, this field can be used to target only an existing application. In Learning mode, this field can either target an existing application or use an automatic method, such as automatic computer, group, or system Learning. Automatic computer Learning ("autocomp") will automatically create applications and apply new policies at the computer level. Automatic group Learning (“autogroup”) will automatically create applications and apply new policies at the group level. Automatic system Learning ("autosystem") will only automatically learn drivers and miscellaneous Windows files, applying only to the individual system. If one of these Maintenance Modes is not in use, it is okay to leave this field as "". When enabling Installation Legacy or Learning mode via this API, be sure to use applicationIds that are accessible within the organization where the computer is located. For example, a child organization cannot use another child organization's application, as it will be inaccessible. This field expects one of the following entries when using Installation or Learning mode:
- Learning and Installation: applicationId in format "00000000-0000-0000-0000-000000000000"
- Learning only: autocomp
- Learning only: autogroup
- Learning only: autosystem
- computerDetailDto: This field specifies the computer, organization, Maintenance Mode type, and Maintenance Mode start and end dates and times.
- computerId: This field expects the computerId of the computer where the Maintenance Mode will be enabled.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerName: This field expects the hostname of the computer on which the Maintenance Mode will be enabled.
- Expects: Text of the hostname
- maintenanceEndDate: This field specifies when the Maintenance Mode will end on a computer. This expects a time entered in UTC in format "YYYY-MM-DDTHH:MM:SSZ", where YYYY is the year, the first MM is the month, DD is the day, HH are the hours, the second MM are the minutes, and SS are the seconds. The T must be included to designate the time and should not be changed or removed.
- Expects end date and time in format: "YYYY-MM-DDTHH:MM:SSZ"
- maintenanceTypeId: This field specifies the Maintenance Mode that will be enabled on the computer. This field expects the Integer associated with the maintenanceTypeId:
- Application Control Monitor Only = 1
- Application Control Learning = 3
- Elevation Mode = 4
- Secured = 8
- Disable ThreatLocker Detect = 16
- Network Control Monitor Only = 17
- Storage Control Monitor Only = 18
- Installation Legacy = 19
- organizationId: This field expects the organizationId of the organization in which the computer that will have the Maintenance Mode enabled exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field expects the computerId of the computer where the Maintenance Mode will be enabled.
- applicationId: This field is used when enabling either the Installation Legacy or Application Control Learning Mode Maintenance Mode on a computer. With Installation Legacy, this field can be used to target only an existing application. In Learning mode, this field can either target an existing application or use an automatic method, such as automatic computer, group, or system Learning. Automatic computer Learning ("autocomp") will automatically create applications and apply new policies at the computer level. Automatic group Learning (“autogroup”) will automatically create applications and apply new policies at the group level. Automatic system Learning ("autosystem") will only automatically learn drivers and miscellaneous Windows files, applying only to the individual system. If one of these Maintenance Modes is not in use, it is okay to leave this field as "". When enabling Installation Legacy or Learning mode via this API, be sure to use applicationIds that are accessible within the organization where the computer is located. For example, a child organization cannot use another child organization's application, as it will be inaccessible. This field expects one of the following entries when using Installation or Learning mode:
- Fields
Required body
{
"applicationId": "00000000-0000-0000-0000-000000000000",
"computerDetailDto": {
"computerId": "00000000-0000-0000-0000-000000000000",
"computerName": "<String>",
"maintenanceEndDate": "YYYY-MM-DDTHH:MM:SSZ",
"maintenanceTypeId": <Integer>,
"organizationId": "00000000-0000-0000-0000-000000000000"
}
}
- Optional Body/Parameters
- N/A
- Permission Requirements
- Assign any one of the following permissions:
- Edit Computers
- View Computers
- AND Assign any one of the following permissions, assign the corresponding permissions:
- Edit Endpoint Detect Remediation
- Edit Endpoint Detect Threats
- Elevation Administrator
- Manage All ThreatLocker Detect Remediation
- Manage All ThreatLocker Detect Threats
- Manage Elevation Mode (Time Restricted)
- Manage Network Control Monitor Only
- Manage Network Control Monitor Mode (Time Restricted)
- Manage Storage Control Monitor Only
- Manage Storage Control Monitor Mode (Time Restricted)
- Assign any one of the following permissions:
The API endpoint below (ComputerUpdateThreatlockerVersionByIds) is now deprecated. Once your ThreatLocker Windows Agents have reached version 10.7.3 or higher, you can no longer use this endpoint for updating your Agents. Please refer to the API Documentation below for the new process of updating your Agents through API:
ComputerUpdateThreatlockerVersionByIds
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateThreatlockerVersionByIds
- Method: POST
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting the checkbox next to one or multiple computers that you want to change/update the ThreatLocker Version on then clicking the "Upgrade Version" button OR clicking on the ThreatLocker Version number on an individual computer in the "TL Version" column in the Portal, selecting which version of ThreatLocker to upgrade/downgrade to OR selecting "Inherit From Group", and then clicking "Change Version" where this API is called. This API will upgrade/downgrade the ThreatLocker Version on a selected computer(s) depending on the fields below.
- Required Body/Parameters
- Fields
- threatLockerVersion: This field is only used when changing the ThreatLocker Version on a computer(s) to "Inherit From Group". It is important that there is no value in the threatLockerVersionId field as any id supplied in that field will overwrite this one.
- Expects: The text "Inherit From Group"
- threatLockerVersionId: This field is used to specify the version of ThreatLocker that the computer(s) will upgrade/downgrade to. To get the ThreatLockerVersionId you would like to use, utilize the ThreatLockerVersionGetForDropdownList API to get all the versions available to be upgraded or downgraded to. Utilize the “label” field to identify which version you would like to upgrade/downgrade to and copy/save the “value” field as this is the id to be supplied in this field.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- computerId: This field is used to determine which computer will have the ThreatLocker Version upgraded/downgraded.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- organizationId: This field is used to specify the organization where the computer that will have the ThreatLocker Version upgraded/downgraded exists.
- Expects: <GUID> in format "00000000-0000-0000-0000-000000000000"
- osType: This field is used to specify the osType of the computer being upgraded/downgraded and expects one of the following Integer values to be entered that correspond to the computer:
- Windows = 1
- MAC = 2
- Linux = 3
- Windows XP = 5
- threatLockerVersion: This field is only used when changing the ThreatLocker Version on a computer(s) to "Inherit From Group". It is important that there is no value in the threatLockerVersionId field as any id supplied in that field will overwrite this one.
- Required body
- The body below, when filled in with corresponding values for each field, will upgrade/downgrade the ThreatLocker Version on two computers. It is important to fill out all the fields for each computer you would like to upgrade/downgrade the ThreatLocker Version on.
{
"threatLockerVersion": "<String>",
"threatLockerVersionId": "00000000-0000-0000-0000-000000000000",
"computerDetailDtos": [
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000",
"osType": <Integer>
},
{
"computerId": "00000000-0000-0000-0000-000000000000",
"organizationId": "00000000-0000-0000-0000-000000000000",
"osType": <Integer>
}
]
}
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
ComputerGetForNewComputer
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerGetForNewComputer
- Method: GET
- Description: This API is used when navigating to the Assets icon and selecting the Computers page in the pop-out menu in the ThreatLocker Portal, then selecting the "Install Computer" button in the top left corner. This API is also used when selecting the "Install Computer" button in the top right corner of any ThreatLocker Portal page. This API returns information related to installing ThreatLocker on a computer. Ensure the managedOrganizationId header matches the location from which you would like to retrieve the installation information.
Listed below are the most relevant fields returned by this API:
- Required Body/Parameters
- N/A
- Optional Body/Parameters
- N/A
-
Permission Requirements
Sample response body
ComputerSignedScriptDownload
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerSignedScriptDownload
- Method: GET
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting from the "Computer Options" hamburger dropdown next to "Install Computer", clicking the "Get Logon Script" button, and then clicking the "Signed Version" button that will call this API to download the signed version of the ThreatLockerVerifier (ThreatLockerVerifier.exe). This file is used for checking if ThreatLocker is installed on computers in an RMM/GPO environment. If any computers without ThreatLocker are found, their information is uploaded to the ThreatLocker Portal under the "Not Installed" tab on the Devices page. Use this in association with the logon batch script that can be located/downloaded either through the ThreatLocker Portal or by using the ComputerSamplePathDownload API below. The response is returned in base 64 which we then use the atob function to blob the string. From there, we send it to the browser for download.
- Required Body/Parameters
- brand: This field always expects the text "Threatlocker" to be entered.
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
- Install Computers
ComputerSamplePathDownload
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerSamplePathDownload
- Method: GET
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting from the "Computer Options" hamburger dropdown next to "Install Computer", clicking the "Get Logon Script" button, and then clicking the "Sample Batch" button that will call this API to download the batch script (sample.bat). This script can call either version of the ThreatLockerVerifier which is used for checking if ThreatLocker is installed on computers in an RMM/GPO environment. If any computers without ThreatLocker are found, their information is uploaded to the ThreatLocker Portal under the "Not Installed" tab on the Devices page. Be sure the file paths used inside the script will be able to find and execute the ThreatLockerVerifier file to successfully check if ThreatLocker is installed on the computer(s). The response is returned in base 64 which we then use the atob function to blob the string. From there, we send it to the browser for download.
- Required Body/Parameters
- brand: This field always expects the text "Threatlocker" to be entered.
- authKey: This field expects the authKey from the organization to be entered. Each organization has a different authKey value. This value can be found by using the OrganizationGetAuthKeyById API located within the KB article below:
/portalAPI/Organization/* | ThreatLocker Help Center
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
- Install Computers
ComputerUnSignedScriptDownload
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUnSignedScriptDownload
- Method: GET
- Description: This API is used on the Devices page in the ThreatLocker Portal when selecting from the "Computer Options" hamburger dropdown next to "Install Computer", clicking the "Get Logon Script" button, and then clicking the "Unsigned Version" button that will call this API to download the unsigned version of the ThreatLockerVerifier (ThreatLockerVerifier-Unsigned.exe). This file is used for checking if ThreatLocker is installed on computers in an RMM/GPO environment. If any computers without ThreatLocker are found, their information is uploaded to the ThreatLocker Portal under the "Not Installed" tab on the Devices page. Use this in association with the logon batch script that can be located/downloaded either through the ThreatLocker Portal or by using the ComputerSamplePathDownload API above. This version is smaller than the signed version. The response is returned in base 64 which we then use the atob function to blob the string. From there, we send it to the browser for download.
- Required Body/Parameters
- brand: This field always expects the text "Threatlocker" to be entered.
- Optional Body/Parameters
- N/A
- Permissions Needed for User
- Edit Computers
- Install Computers
ComputerUpdateForDeleteByIds
https://portalapi.INSTANCE.threatlocker.com/portalapi/Computer/ComputerUpdateForDeleteByIds
- Method: POST
- Description: This API is used when navigating to the Assets icon and selecting the Computers page from the pop-out menu in the ThreatLocker Portal, selecting the checkbox next to one or multiple computers, and then selecting the "Delete" button to delete the computer(s) from the organization. This API deletes/removes computers from your organization's ThreatLocker Portal. Ensure that the managedOrganizationId header you use matches the location from which the computer(s) will be deleted.
A separate process for uninstalling the ThreatLocker agent is recommended over only deleting the computer from the Portal, documentation linked below. This API call will not uninstall the ThreatLocker agent from a computer. It will only remove it from your Portal.Uninstalling the ThreatLocker Agent | ThreatLocker Help Center
If the deleted computer comes back online, it will automatically be re-added to the Portal, and all of its previous policies will be lost.
- Required Body/Parameters
- Fields
Note: Each of the following fields needs to be entered for each computer you want to delete, as shown in the Required body section.
-
-
-
computerId: This field determines which computer will be deleted from the ThreatLocker Portal. This field expects the computerId of the computer that will be deleted.
-
organizationId: This field expects the organizationId of the organization where the computer is currently installed and from which it will be deleted. The organizationId should match the managedOrganizationId header used.
-
-
Required body
- Optional Body/Parameters
- N/A
- Permission Requirements
- Assign this permission:
- Edit Computers
- Assign this permission:
Help Center