# Fetch the list of all CIS compliance policy groups Retrieves all custom CIS compliance policy groups for the given customer, including policy group ID, name, type, platform, and icon details. ## Endpoint `GET /dcapi/scap/compliance/policygroups` ## Request URL `https://`[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)`/dcapi/scap/compliance/policygroups` ## Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/policygroups \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP code 200 Response Body — `application/json` **JSON Object** - **policyGrpId** (`long`): Unique identifier of the policy group - **policyGrpType** (`string`): Policy group type. 0 = default (CRS), 1 = custom - **policyGrpName** (`string`): Name of the policy group - **platform** (`string`): Platform identifier. 1 = Windows, 3 = Linux - **image** (`string`): Platform icon image path ### Sample Response: HTTP 200 List of all custom CIS compliance policy groups ```json [ { "image": "/images/windows.png", "policyGrpType": 1, "policyGrpName": "Windows CIS L1 Policy", "platform": 1, "policyGrpId": 1001 }, { "image": "/images/linux_icon.png", "policyGrpType": 0, "policyGrpName": "Linux CIS L2 Policy", "platform": 3, "policyGrpId": 1002 } ] ``` ### HTTP code 401 Response Body — `application/json` **JSON Object** - **errorCode** (`long`): Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) - **errorMsg** (`string`): Authentication failure reason ### Sample Response: HTTP 401 Authentication credentials are missing or invalid ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### HTTP code 429 Response Body — `application/json` **JSON Object** - **errorCode** (`long`): Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes - **errorMsg** (`string`): Rate limit exceeded message with retry guidance ### Sample Response: HTTP 429 API call threshold exceeded ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.