# Configures a new privilege elevation application group Creates the privilege application group and populates it with applications that standard users may elevate. Prefetch vendorID or productVendorID from [Get App Rule Types](https://www.manageengine.com/products/desktop-central/help/api/cloud/acp-get-app-rule-types.html) and supply them as verifiedAppRepoIDs in addedRules. ## Endpoint **POST** `/dcapi/appctrl/privilegeAppGroup` ## Request URL `https://`[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)`/dcapi/appctrl/privilegeAppGroup` ## Scope `DesktopCentralCloud.AppControl.CREATE` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers | Parameter | Type | Required | Value | |---|---|---|---| | Content-Type | string | Mandatory | `application/addUpdatePrivilegeAppGroup.v1+json` | | Accept | string | Mandatory | `application/addUpdatePrivilegeAppGroup.v1+json` | ### Request Body `application/json` - JSON Object - **jitRequestMode** — `string` — Mandatory JIT request mode (0=Disabled, 1=Enabled, 2=Approval Required) - **configSpecificAppEnabled** — `boolean` — Mandatory Whether config-specific app elevation is enabled - **appGroupType** — `integer` — Mandatory Type of application group (3=Privilege) - **addedRules** — `JSON Array` — Mandatory Rules to add - **removedRules** — `array` — Mandatory Empty Array For Creation ### Sample Request ```curl curl --request POST \ --url https://appdomains/dcapi/appctrl/privilegeAppGroup \ --header 'Accept: application/addUpdatePrivilegeAppGroup.v1+json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/addUpdatePrivilegeAppGroup.v1+json' \ --data '{"removedRules":[],"appGroupType":3,"configSpecificAppEnabled":true,"jitRequestMode":"1","addedRules":[{"appRuleType":1}]}' ``` ### Sample Request Body Create a privilege group with specific vendor-based apps for elevation. ```json { "removedRules": [], "appGroupType": 3, "configSpecificAppEnabled": true, "jitRequestMode": "1", "addedRules": [ { "appRuleType": 1, "verifiedAppRepoIDs": [ 610, 611 ] } ] } ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` - JSON Object - **status** — `boolean` Whether the operation completed successfully (true=success, false=failure) ### HTTP Code 401 Response Body — `application/json` - JSON Object - **errorCode** — `long` Unauthorized error code: credentials missing, expired, or invalid - **errorMsg** — `string` Authentication failure reason ### HTTP Code 500 Response Body — `application/json` - JSON Object - **errorCode** — `string` Internal error code: INTERNAL_ERROR when exception occurs creating privilege app group - **errorMessage** — `string` Detailed message: Error Occurred while add or update privilege app group ### Possible Response Codes - `200` — HTTP code - `401` — HTTP code - `500` — HTTP code ### Sample Response: HTTP 200 Privilege application group created successfully. ```json { "status": true } ``` ### Sample Response: HTTP 401 Authentication credentials missing or invalid. ```json { "errorMessage": "Authentication credentials are missing or invalid", "errorCode": "UNAUTHORIZED" } ``` ### Sample Response: HTTP 500 Internal error while creating privilege app group. ```json { "errorMessage": "Error Occurred while add or update privilege app group", "errorCode": "INTERNAL_ERROR" } ``` ## API Rate Limits **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration — Time window for the threshold. Threshold — Number of API calls allowed within the specified duration. Lock Period — Wait time before consecutive API requests.