# Fetch the profiles associated with a policy group Retrieves the policy group name and its associated CIS benchmark profiles for the specified policy group ID. ## Endpoint `GET /dcapi/scap/compliance/policygroups/{policyGrpId}/profiles` ## Request URL `https://{serverurl}/dcapi/scap/compliance/policygroups/{policyGrpId}/profiles` For server URL details, see [OAuth Authentication Endpoint Domain](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html). ## Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Path Parameters **policyGrpId** `string` **Mandatory** The ID of the policy group. Fetch from [List Policy Groups](https://www.manageengine.com/products/desktop-central/help/api/cloud/list-policy-groups.html). ## Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/policygroups/{policyGrpId}/profiles \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP code 200 Response Body: `application/json` `JSON Object` - **grpName** `string`: Name of the policy group - **profiles** `JSON Array`: List of associated CIS benchmark profiles ### Sample Response: HTTP 200 Policy group with associated CIS benchmark profiles ```json { "profiles": [ { "id": 50001, "type": 1 }, { "id": 50002, "type": 1 } ], "grpName": "Windows CIS Level 1 Policy" } ``` ### HTTP code 401 Response Body: `application/json` `JSON Object` - **errorCode** `long`: Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) - **errorMsg** `string`: Authentication failure reason ### Sample Response: HTTP 401 Authentication credentials are missing or invalid ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### HTTP code 429 Response Body: `application/json` `JSON Object` - **errorCode** `long`: Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes - **errorMsg** `string`: Rate limit exceeded message with retry guidance ### Sample Response: HTTP 429 API call threshold exceeded ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ![ ](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.