# Create a new CIS compliance policy group Creates a new custom CIS compliance policy group with the specified name, platform, and associated benchmark profiles. ## Endpoint `POST /dcapi/scap/compliance/policygroups` ## Request ### Request URL `https://[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)/dcapi/scap/compliance/policygroups` ### Scope `DesktopCentralCloud.VulnerabilityMgmt.CREATE` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ### Request Parameters #### Request Headers - **Content-Type** `string` — **Mandatory** - `application/createPolicyGrp.v1+json` - **Accept** `string` — **Mandatory** - `application/createPolicyGrp.v1+json` #### Request Body `application/json` - `JSON Object` - **profiles** `JSON Array` — Optional - List of CIS benchmark profile objects to associate with the policy group. Fetch available profiles from [Get Profiles List for Platform](https://www.manageengine.com/products/desktop-central/help/api/cloud/get-profiles-list-for-platform.html). - **groupName** `string` — Optional - Name of the policy group - **platform** `string` — Optional - Platform identifier. `1 = Windows`, `3 = Linux` ### Sample Request ```curl curl --request POST \ --url https://appdomains/dcapi/scap/compliance/policygroups \ --header 'Accept: application/createPolicyGrp.v1+json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/createPolicyGrp.v1+json' \ --data '{}' ``` ### Sample Request Body Create a new custom CIS compliance policy group with benchmark profiles. ```json { "groupName": "Windows CIS Level 1 Policy", "profiles": [ { "id": "50001", "type": 1 }, { "id": "50002", "type": 1 } ], "platform": 1 } ``` ## Response Parameters ### HTTP Code 200 Response body: `application/json` - `JSON Object` - **status** `boolean` - `true` if the policy group was created successfully, `false` otherwise ### HTTP Code 400 Response body: `application/json` - `JSON Object` - **statusCode** `string` - HTTP status code (`400`) - **errorCode** `string` - API-specific error code identifying the validation failure - **message** `string` - Error message describing the validation failure ### HTTP Code 401 Response body: `application/json` - `JSON Object` - **errorCode** `long` - Unauthorized error code returned when authentication credentials are missing, expired, or invalid (`authentication=required`) - **errorMsg** `string` - Authentication failure reason ### HTTP Code 429 Response body: `application/json` - `JSON Object` - **errorCode** `long` - Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes - **errorMsg** `string` - Rate limit exceeded message with retry guidance ## Sample Responses ### HTTP 200 Policy group created successfully. ```json { "status": true } ``` Policy group creation failed. ```json { "status": false } ``` ### HTTP 400 A request body parameter has an invalid format or type. ```json { "errorCode": "IAM0025", "url": "/dcapi/scap/compliance/policygroups", "errorMsg": "id is an invalid parameter format." } ``` ### HTTP 401 Authentication credentials are missing or invalid. ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### HTTP 429 API call threshold exceeded. ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.