APINHI

Triage an NHI finding

Triage a finding: acknowledge, dismiss, or reopen it.

PATCH
/nhi/findings/{finding_id}

Triage a finding: acknowledge, dismiss, or reopen it.

Authorization

ApiKeyAuth
headerAuthorizationBearer <token>

Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.

Required permission

manage_nhi

Path Parameters

finding_id*string
Formatuuid

Request Body

application/json
  1. body
status*string

resolved is set only by a sync and is refused with 400.

Value in"open""acknowledged""dismissed""resolved"

Response Body

The request has succeeded.

application/json
  1. response

One rule's assertion about one identity, as the last complete walk left it. A finding disappears when a later walk no longer asserts it.

id*uuid
Formatuuid
source_id*uuid
Formatuuid
rule*NhiRule

A rule in the detection pack, listed worst severity first.

Value in"secret_never_expires""live_secret_disabled_principal""disabled_by_microsoft""owner_account_disabled""app_only_directory_authority""open_beyond_tenant""secret_older_than_max_age""credential_sprawl""legacy_service_principal_credentials""tenant_wide_admin_consent""broad_sensitive_scopes""external_idp_trust""expired_credentials_present""disabled_principal_present""unverified_publisher""ownerless_identity""agent_identity_sprawl""blueprint_without_agent_identities""duplicate_registration""application_without_service_principal"
severity*string

Derived from the rule, not stored on the finding.

Value in"low""medium""high""critical"
kind*NhiIdentityKind

The kind of directory object a finding is about. A walk also returns the relationships between them, but those are joined into a finding's subject rather than being one.

Value in"application""agent_identity_blueprint""service_principal""agent_identity""user""agent_user"
external_id*string

The provider's id for the subject.

display_name*string
first_seen_at*string

When this finding was first asserted.

Formatdate-time
last_seen_at*string

The most recent walk that still asserted it.

Formatdate-time
status*NhiFindingStatus

Where a finding sits in triage. Only a directory sync sets resolved.

Value in"open""acknowledged""dismissed""resolved"
status_changed_at?string

When the status last changed, by triage or by a sync resolving it; absent while never triaged.

Formatdate-time
evidence*

Why a rule fired, shaped per directory and discriminated on provider.

curl -X PATCH "https://example.com/nhi/findings/497f6eca-6276-4993-bfeb-53cbbbba6f08" \  -H "Content-Type: application/json" \  -d '{    "status": "open"  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "source_id": "ae50a35c-df42-4eff-ba26-f8bc28d2af81",  "rule": "secret_never_expires",  "severity": "low",  "kind": "application",  "external_id": "string",  "display_name": "string",  "first_seen_at": "2019-08-24T14:15:22Z",  "last_seen_at": "2019-08-24T14:15:22Z",  "status": "open",  "status_changed_at": "2019-08-24T14:15:22Z",  "evidence": {    "provider": "microsoft_entra",    "credentials": [      {        "key_id": "string",        "display_name": "string",        "type": "password",        "expires_at": "2019-08-24T14:15:22Z",        "years_out": 0      }    ],    "principal": {      "object_id": "string",      "account_enabled": true    },    "audience": {      "sign_in_audience": "string"    },    "sprawl": {      "count": 0,      "window_days": 0,      "threshold": 0    },    "orphan": {      "age_days": 0,      "grace_days": 0    }  }}