# Retrieve restriction settings applied to a managed device gets the restriction of the device ## Endpoint `GET /api/v1/mdm/devices/{device_id}/restrictions` ## Request URL `https://{server-hostname}:8383/api/v1/mdm/devices/{device_id}/restrictions` ## Scope `MDMInventory.READ` ## Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Accept** `string` — **Mandatory** — `application/json` ### Path Parameters - **device_id** `string` — **Mandatory** Unique identifier of the device. Obtain from the [Get Device List](https://www.manageengine.com/products/desktop-central/help/api/onpremise/devices-get-device-list.html) response ### Query Parameters - **limit** `integer` — Optional Maximum number of records to return in a single response. Used together with offset for pagination - **skip-token** `string` — Optional Pagination continuation token returned by a previous response. Pass it to fetch the next page of results - **offset** `integer` — Optional Zero-based index of the first record to return. Used together with limit for pagination - **delta-token** `string` — Optional Token used for delta/incremental fetches. Pass the token returned from a previous response to retrieve only items modified since that point - **searchkey** `string` — Optional Value to search for. Must be used in combination with searchfield to specify which field is searched - **searchfield** `string` — Optional Name of the field to search against. Used together with searchkey (e.g., name, email, udid) - **is_allowed_apps** `boolean` — Optional Set to true to return apps from the allow list, false to return apps from the block list - **is_app_purchased_from_portal** `boolean` — Optional Set to true to restrict results to apps purchased through the enterprise app portal (VPP/managed Google Play). Default: false - **search** `string` — Optional Free-text search string applied to the default searchable fields of the resource - **app_scope** `string` — Optional Filter applications by their assignment scope. Allowed values: 1=All, 2=Assigned to groups, 3=Assigned to devices - **platform** `string` — Optional Filter results by device platform. Allowed values: 1=iOS, 2=Android, 3=Windows, 4=macOS, 6=tvOS ## Sample Request ```curl curl --request GET \ --url 'https://appdomain/api/v1/mdm/devices/{device_id}/restrictions?limit=SOME_INTEGER_VALUE&skip-token=SOME_STRING_VALUE&offset=SOME_INTEGER_VALUE&delta-token=SOME_STRING_VALUE&searchkey=SOME_STRING_VALUE&searchfield=SOME_STRING_VALUE&is_allowed_apps=SOME_BOOLEAN_VALUE&is_app_purchased_from_portal=SOME_BOOLEAN_VALUE&search=SOME_STRING_VALUE&app_scope=SOME_STRING_VALUE&platform=SOME_STRING_VALUE' \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 #### Response Body — application/json `JSON Object` - **allow_inapp_purchase** `integer` In-app purchase: 0 - Restricted, 1 - Allowed - **allow_app_removal** `integer` App removal: 0 - Restricted, 1 - Allowed - **allow_news** `integer` News: 0 - Restricted, 1 - Allowed - **allow_profile_installation** `integer` Profile installation: 0 - Restricted, 1 - Allowed - **allow_airdrop** `integer` AirDrop: 0 - Restricted, 1 - Allowed - **allow_cloud_backup** `integer` Cloud backup: 0 - Restricted, 1 - Allowed - **allow_assistant** `integer` Siri: 0 - Restricted, 1 - Allowed - **allow_safari** `integer` Safari browser: 0 - Restricted, 1 - Allowed - **camera** `integer` Camera (Windows/Android): 0 - Restricted, 1 - Allowed - **bluetooth** `integer` Bluetooth (Windows): 0 - Restricted, 1 - Allowed - **browser** `integer` Browser (Windows): 0 - Restricted, 1 - Allowed - **copy_paste** `integer` Copy/paste (Windows): 0 - Restricted, 1 - Allowed - **screen_capture** `integer` Screen capture (Windows): 0 - Restricted, 1 - Allowed - **allow_autofill** `integer` Browser autofill: 0 - Restricted, 1 - Allowed - **allow_cookies** `integer` Browser cookies: 0 - Restricted, 1 - Allowed - **allow_popups** `integer` Browser pop-ups: 0 - Allowed, 1 - Restricted - **knox_restricions** `JSON Object` Samsung Knox-specific restriction settings ## Possible Response Codes - **200** `HTTP code` ## Sample Response: HTTP 200 iOS, Android, Windows, and Knox restriction settings ```json { "knox_restricions": { "allow_camera": "1", "allow_wifi": "-1", "allow_bluetooth": "-1", "allow_screen_capture": "0" }, "allow_assistant": 1, "allow_popups": 0, "allow_safari": 1, "allow_inapp_purchase": 0, "allow_cloud_backup": 1, "allow_app_removal": 1, "allow_airdrop": 0, "allow_news": 0, "allow_cookies": 1, "bluetooth": 0, "copy_paste": 0, "allow_autofill": 0, "browser": 1, "screen_capture": 0, "allow_profile_installation": 0, "camera": 1 } ``` ## Rate Limits **Duration:** 1 minute | **Threshold:** 250 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.