Retrieves detailed information about a specific CIS benchmark rule including description, rationale, remediation steps, and for scanned resources: expected vs actual values and audit remarks
get /dcapi/scap/compliance/benchmark/rules/{ruleId}
https://{server-hostname}:8383/dcapi/scap/compliance/benchmark/rules/{ruleId}
VulnerabilityMgmt.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Rule identifier. Fetch from Get Benchmark Details response steps[].children[].itemId where type is rule
curl --request GET \
--url https://appdomain/dcapi/scap/compliance/benchmark/rules/{ruleId} \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'The queried rule ID
Rule description (sanitized HTML)
Why this rule matters (sanitized HTML)
Remediation instructions (sanitized HTML)
Expected vs actual values with HTML formatting. Only present when resourceId and collectionId are provided
Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Rule details with scan results showing expected vs actual values
{
"summary": "Ensure Account lockout threshold is set to 5 or fewer invalid logon attempts",
"reason": "<b>Expected value :</b> 5<br><br><b>Current value :</b> 10<br><br><b>Registry path :</b> HKLM\\SOFTWARE\\...",
"fix": "To establish the recommended configuration via GP, set the following UI path to 5 or fewer but not 0: Computer Configuration\\Policies\\Windows Settings\\Security Settings\\Account Policies\\Account lockout threshold",
"ruleId": "1001",
"rationale": "Setting an account lockout threshold reduces the likelihood that an online password brute force attack will be successful"
}
Rule details without resource-specific scan data
{
"summary": "Ensure Account lockout threshold is set to 5 or fewer invalid logon attempts",
"fix": "To establish the recommended configuration via GP, set the following UI path to 5 or fewer but not 0",
"ruleId": "1001",
"rationale": "Setting an account lockout threshold reduces the likelihood that an online password brute force attack will be successful"
}
Authentication credentials are missing or invalid
{
"errorMessage": "Authentication required",
"errorCode": "UNAUTHORIZED"
}
API call threshold exceeded
{
"errorMessage": "Rate limit exceeded. Retry after some time",
"errorCode": "TOO_MANY_REQUESTS"
}
![]()
Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.