Retrieves all CIS compliance profile results for a specific resource within a custom group, showing each benchmark profile's scan status, pass/fail percentage, and rules breakdown
https://{server-hostname}:8383/dcapi/scap/compliance/result/profiles/{resourceId}
VulnerabilityMgmt.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Computer/resource ID. Fetch from Get CG Association Details resource listing
curl --request GET \
--url https://appdomain/dcapi/scap/compliance/result/profiles/{resourceId} \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'Name of the computer
Custom group name
List of benchmark profiles with scan results
Profile ID
Profile type. 1 = XCCDF, 0 = OVAL
Benchmark profile title
SCAP standard type
Results summary, e.g., 200/245 Rules Passed or NA
Pass percentage (0-100)
Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Profile scan results for a specific resource
{
"resourceName": "WIN-SERVER-01",
"benchmarks": [
{
"result": "200/245 Rules Passed",
"scapType": "XCCDF",
"profileType": 1,
"profileId": 50001,
"title": "CIS Microsoft Windows Server 2019 Benchmark - Level 1",
"successPercentage": 82
},
{
"result": "NA",
"scapType": "XCCDF",
"profileType": 1,
"profileId": 50002,
"title": "CIS Microsoft Windows Server 2019 Benchmark - Level 2",
"successPercentage": 0
}
],
"cgName": "Production Servers"
}
Authentication credentials are missing or invalid
{
"errorMessage": "Authentication required",
"errorCode": "UNAUTHORIZED"
}
API call threshold exceeded
{
"errorMessage": "Rate limit exceeded. Retry after some time",
"errorCode": "TOO_MANY_REQUESTS"
}
![]()
Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.