# Retrieve the full FileVault encryption settings details for a given encryption_settings_id Get the file vault settings details ## Endpoints **GET** `/api/v1/mdm/profiles/filevaults/{encryption_settings_id}` ## Request URL ``` https://{serverurl}/api/v1/mdm/profiles/filevaults/{encryption_settings_id} ``` ## Scope ``` MDMOnDemand.MDMDeviceMgmt.READ ``` ## Header ``` Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52 ``` ## Request Parameters ### Path Parameters - **encryption_settings_id** `string` (Mandatory) Unique identifier of the encryption settings. Obtain from the response of [Create FileVault Encryption Settings API](https://www.manageengine.com/mobile-device-management/mac-add-filevault-encryption-settings.html) ## Sample Request ### Curl ```bash curl --request GET \ --url https://appdomain/api/v1/mdm/profiles/filevaults/{encryption_settings_id} \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ### Java ```java import java.net.URI; import java.net.http.HttpClient; import java.net.http.HttpRequest; import java.net.http.HttpResponse; import java.io.IOException; import java.net.http.HttpTimeoutException; public class Main { public static void main(String[] args) { HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("https://appdomain/api/v1/mdm/profiles/filevaults/{encryption_settings_id}")) .header("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") .method("GET", HttpRequest.BodyPublishers.noBody()) .build(); HttpResponse response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString()); System.out.println(response.body()); } } ``` ### Python ```python import http.client conn = http.client.HTTPSConnection("appdomain") headers = { 'Authorization': "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52" } conn.request("GET", "/api/v1/mdm/profiles/filevaults/{encryption_settings_id}", headers=headers) res = conn.getresponse() data = res.read() print(data.decode("utf-8")) ``` ### Deluge ```javascript headersMap = Map(); headersMap.put("Accept", "application/json"); response = invokeUrl [ url: "https://appDomain/api/v1/mdm/profiles/filevaults/{encryption_settings_id}" type: GET headers: headersMap connection: connection_name ] info response; ``` ### PowerShell ```powershell $headers=@{} $headers.Add("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") $response = Invoke-WebRequest -Uri 'https://appdomain/api/v1/mdm/profiles/filevaults/{encryption_settings_id}' -Method GET -Headers $headers ``` ## Response Parameters ### HTTP 200 Response Body: `application/json` - **mdmencryptionsettings** `JSON object` Core encryption settings with assigned encryption_settings_id - **encryption_settings_id** `long` Unique identifier for the encryption settings - **settings_name** `string` Name of the encryption settings configuration - **encryption_settings_type** `string` Type of recovery key. Values: - `1` = Personal Recovery Key - `2` = Institutional Recovery Key - `3` = Personal and Institutional Recovery Key - **settings_desc** `string` Description of the encryption settings - **customer_id** `long` Customer ID associated with the settings - **added_user** `long` User ID who created the settings - **modified_user** `long` User ID who last modified the settings - **added_time** `string` Epoch timestamp (milliseconds) when settings were created - **modified_time** `string` Epoch timestamp (milliseconds) when settings were last modified - **mdmfilevaultsettings** `JSON object` FileVault-specific settings - **recovery_key_type** `string` Recovery key type. Values: - `1` = Personal Recovery Key - `2` = Institutional Recovery Key - `3` = Both - **message_to_user** `string` Message shown to the user about the recovery key escrow location - **dont_allow_filevault_disable** `boolean` Whether users are restricted from turning off FileVault - **copy_recovery_key_to_mdm** `boolean` Whether recovery key is copied to MDM server - **force_encryption_until_logout** `boolean` Whether encryption is forced at the next logout - **ask_enable_during_logout** `boolean` Whether user is prompted to enable FileVault during logout - **maximum_attempts_to_force** `string` Maximum login bypass attempts before enforcement. - `-1` = disabled - `0` = enforce at next login - **mdmfilevaultpersonalkeyconfiguration** `JSON object` Personal recovery key configuration with assigned certificate IDs (present when `encryption_settings_type` is `1` or `3`) - **show_recovery_key** `boolean` Whether personal recovery key is displayed to user - **enable_ec_agent_prk_rotation** `boolean` Whether automatic personal recovery key rotation is enabled - **recovery_key_identifier** `string` Identifier for the recovery key certificate - **recovery_encrypt_cert_id** `string` Certificate ID used to encrypt the personal recovery key - **mdmfilevaultinstitutionconfiguration** `JSON object` Institutional recovery key configuration (present when `encryption_settings_type` is `2` or `3`) - **institution_encryption_cert** `string` Certificate ID used for institutional recovery key encryption ## Sample Response: HTTP 200 FileVault encryption settings details (Personal and Institutional) ```json { "mdmfilevaultsettings": { "copy_recovery_key_to_mdm": true, "dont_allow_filevault_disable": false, "recovery_key_type": "3", "maximum_attempts_to_force": "-1", "force_encryption_until_logout": false, "ask_enable_during_logout": false, "message_to_user": "The personal recovery key is stored in the MDM server. Contact your administrator to retrieve it." }, "mdmfilevaultinstitutionconfiguration": { "institution_encryption_cert": "6967000001030029" }, "mdmfilevaultpersonalkeyconfiguration": { "show_recovery_key": false, "recovery_key_identifier": "6967000001030023", "enable_ec_agent_prk_rotation": false, "recovery_encrypt_cert_id": "6967000001030023" }, "mdmencryptionsettings": { "modified_user": "6967000000047005", "added_time": "1777444564220", "modified_time": "1777444564220", "encryption_settings_type": "3", "added_user": "6967000000047005", "settings_desc": "", "customer_id": "6967000000047017", "encryption_settings_id": "6967000001030020", "settings_name": "Combined FileVault Settings" } } ``` ## Possible HTTP Status Codes - **200** – OK ## Rate Limit **Duration:** 1 minute **Threshold:** 120 **Lock period:** 5 minutes - **Duration** – Time window for the threshold. - **Threshold** – Number of API calls allowed within the specified duration. - **Lock Period** – Wait time before consecutive API requests.