Get an NHI finding
Get a finding by ID.
Get a finding by ID.
ApiKeyAuthAuthorizationBearer <token>Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.
Required permission
view_nhifinding_id*stringuuidThe request has succeeded.
application/json- response
One rule's assertion about one identity, as the last complete walk left it. A finding disappears when a later walk no longer asserts it.
id*uuiduuidsource_id*uuiduuidrule*NhiRuleA rule in the detection pack, listed worst severity first.
"secret_never_expires""live_secret_disabled_principal""disabled_by_microsoft""owner_account_disabled""app_only_directory_authority""open_beyond_tenant""secret_older_than_max_age""credential_sprawl""legacy_service_principal_credentials""tenant_wide_admin_consent""broad_sensitive_scopes""external_idp_trust""expired_credentials_present""disabled_principal_present""unverified_publisher""ownerless_identity""agent_identity_sprawl""blueprint_without_agent_identities""duplicate_registration""application_without_service_principal"severity*stringDerived from the rule, not stored on the finding.
"low""medium""high""critical"kind*NhiIdentityKindThe kind of directory object a finding is about. A walk also returns the relationships between them, but those are joined into a finding's subject rather than being one.
"application""agent_identity_blueprint""service_principal""agent_identity""user""agent_user"external_id*stringThe provider's id for the subject.
display_name*stringfirst_seen_at*stringWhen this finding was first asserted.
date-timelast_seen_at*stringThe most recent walk that still asserted it.
date-timestatus*NhiFindingStatusWhere a finding sits in triage. Only a directory sync sets resolved.
"open""acknowledged""dismissed""resolved"status_changed_at?stringWhen the status last changed, by triage or by a sync resolving it; absent while never triaged.
date-timeevidence*Why a rule fired, shaped per directory and discriminated on provider.
curl -X GET "https://example.com/nhi/findings/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "source_id": "ae50a35c-df42-4eff-ba26-f8bc28d2af81", "rule": "secret_never_expires", "severity": "low", "kind": "application", "external_id": "string", "display_name": "string", "first_seen_at": "2019-08-24T14:15:22Z", "last_seen_at": "2019-08-24T14:15:22Z", "status": "open", "status_changed_at": "2019-08-24T14:15:22Z", "evidence": { "provider": "microsoft_entra", "credentials": [ { "key_id": "string", "display_name": "string", "type": "password", "expires_at": "2019-08-24T14:15:22Z", "years_out": 0 } ], "principal": { "object_id": "string", "account_enabled": true }, "audience": { "sign_in_audience": "string" }, "sprawl": { "count": 0, "window_days": 0, "threshold": 0 }, "orphan": { "age_days": 0, "grace_days": 0 } }}