openapi: 3.2.0 info: title: Cisco ISE API - Policy Device Admin - MFA Rules API version: 1.0.0 x-provenance: method: harvested authored_by: Cisco harvested_by: API Evangelist harvested_on: '2026-08-19' first_party: true provider_published: true source_host: pubhub.devnetcloud.com note: 103 ISE API descriptions (1,490 operations; 32 OpenAPI 3.0.x + 71 Swagger 2.0) enumerated from Cisco's own DevNet project manifest and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source. x-evidence: - type: source url: https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/ - type: source url: https://developer.cisco.com/docs/identity-services-engine/ servers: - url: https://172.23.9.91:443 description: Inferred Url tags: - name: Device Admin - MFA Rules paths: /api/v1/policy/device-admin/policy-set/{policyId}/mfa: get: tags: - Device Admin - MFA Rules summary: Device Admin - Get MFA rules. description: Device Admin - Get MFA rules. operationId: getDeviceAdminPolicyByIdMfaRuleList parameters: - name: policyId in: path description: Policy id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: X-Request-ID in: header description: request Id, will return in the response headers, and appear in logs required: false schema: type: string exampleSetFlag: true responses: '200': description: MFA Rule list response content: application/json: schema: $ref: '#/components/schemas/MfaRuleListResponseEntity' exampleSetFlag: false '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false '401': description: Unauthorized '403': description: Forbidden '404': description: The specified resource was not found content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false security: - BasicAuth: [] post: tags: - Device Admin - MFA Rules summary: Device Admin - Create MFA rule. description: 'Device Admin - Create MFA rule: ' operationId: createDeviceAdminPolicyByIdMfaRule parameters: - name: policyId in: path description: Policy id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: X-Request-ID in: header description: request Id, will return in the response headers, and appear in logs required: false schema: type: string exampleSetFlag: true requestBody: content: application/json: schema: $ref: '#/components/schemas/RuleMfa' exampleSetFlag: false responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/MfaRuleResponseEntity' exampleSetFlag: false '201': description: MFA Rule list response content: application/json: schema: $ref: '#/components/schemas/MfaRuleResponseEntity' exampleSetFlag: false '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false '401': description: Unauthorized '403': description: Forbidden '404': description: The specified resource was not found content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false security: - BasicAuth: [] /api/v1/policy/device-admin/policy-set/{policyId}/mfa/reset-hitcount: post: tags: - Device Admin - MFA Rules summary: Device Admin - Reset HitCount for MFA Rules description: Device Admin - Reset HitCount for MFA Rules operationId: resetHitCountsDeviceAdminPolicyByIdMfaRules parameters: - name: policyId in: path description: Policy id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: X-Request-ID in: header description: request Id, will return in the response headers, and appear in logs required: false schema: type: string exampleSetFlag: true responses: '200': description: Response with success message content: application/json: schema: $ref: '#/components/schemas/MessageResponseEntity' exampleSetFlag: false '201': description: Created '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false '401': description: Unauthorized '403': description: Forbidden '404': description: The specified resource was not found content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false security: - BasicAuth: [] /api/v1/policy/device-admin/policy-set/{policyId}/mfa/{ruleId}: get: tags: - Device Admin - MFA Rules summary: Device Admin - Get rule attributes. description: Device Admin - Get rule attributes. operationId: getDeviceAdminPolicyByIdMfaRuleById parameters: - name: policyId in: path description: Policy id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: ruleId in: path description: Rule id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: X-Request-ID in: header description: request Id, will return in the response headers, and appear in logs required: false schema: type: string exampleSetFlag: true responses: '200': description: MFA Rule list response content: application/json: schema: $ref: '#/components/schemas/MfaRuleResponseEntity' exampleSetFlag: false '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false '401': description: Unauthorized '403': description: Forbidden '404': description: The specified resource was not found content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false security: - BasicAuth: [] put: tags: - Device Admin - MFA Rules summary: Device Admin - Update rule. description: Device Admin - Update rule. operationId: updateDeviceAdminPolicyByIdMfaRuleById parameters: - name: policyId in: path description: Policy id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: ruleId in: path description: Rule id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: X-Request-ID in: header description: request Id, will return in the response headers, and appear in logs required: false schema: type: string exampleSetFlag: true requestBody: content: application/json: schema: $ref: '#/components/schemas/RuleMfa' exampleSetFlag: false responses: '200': description: MFA Rule list response content: application/json: schema: $ref: '#/components/schemas/MfaRuleResponseEntity' exampleSetFlag: false '201': description: Created '204': description: No Content content: application/json: schema: $ref: '#/components/schemas/MfaRuleResponseEntity' exampleSetFlag: false '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false '401': description: Unauthorized '403': description: Forbidden '404': description: The specified resource was not found content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false security: - BasicAuth: [] delete: tags: - Device Admin - MFA Rules summary: Device Admin - Delete rule. description: Device Admin - Delete rule. operationId: deleteDeviceAdminPolicyByIdMfaRuleById parameters: - name: policyId in: path description: Policy id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: ruleId in: path description: Rule id required: true style: simple schema: type: string format: uuid exampleSetFlag: true - name: X-Request-ID in: header description: request Id, will return in the response headers, and appear in logs required: false schema: type: string exampleSetFlag: true responses: '200': description: Response with object ID content: application/json: schema: $ref: '#/components/schemas/IdResponseEntity' exampleSetFlag: false '202': description: Accepted content: application/json: schema: $ref: '#/components/schemas/IdResponseEntity' exampleSetFlag: false '204': description: No Content content: application/json: schema: $ref: '#/components/schemas/IdResponseEntity' exampleSetFlag: false '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false '401': description: Unauthorized '403': description: Forbidden '404': description: The specified resource was not found content: application/json: schema: $ref: '#/components/schemas/Error' exampleSetFlag: false security: - BasicAuth: [] components: schemas: RuleCommon: title: RuleCommon required: - name type: object properties: condition: $ref: '#/components/schemas/Condition' exampleSetFlag: true default: type: boolean description: Indicates if this rule is the default one example: false exampleSetFlag: true hitCounts: type: integer description: The amount of times the rule was matched format: int32 readOnly: true example: 2 exampleSetFlag: true id: type: string description: The identifier of the rule format: uuid readOnly: true example: d82952cb-b901-4b09-b363-5ebf39bdbaf9 exampleSetFlag: true name: type: string description: Rule name, [Valid characters are alphanumerics, underscore, hyphen, space, period, parentheses] example: MyRuleName_1 exampleSetFlag: true rank: type: integer description: The rank(priority) in relation to other rules. Lower rank is higher priority. format: int32 example: 1 exampleSetFlag: true state: type: string description: The state that the rule is in. A disabled rule cannot be matched. example: enabled exampleSetFlag: true enum: - disabled - enabled - monitor description: Common attributes in rule authentication/authorization exampleSetFlag: false Link: title: Link required: - href type: object properties: href: type: string example: https://{{ISE_IP}}/api/v1/policy/{{protocol}}/policy-set/{{resource-id}} exampleSetFlag: true rel: type: string example: self exampleSetFlag: true enum: - next - previous - self - status type: type: string example: application/json exampleSetFlag: true exampleSetFlag: false MfaRuleResponseEntity: title: MfaRuleResponseEntity required: - response - version type: object properties: response: $ref: '#/components/schemas/RuleMfa' exampleSetFlag: true version: type: string example: 1.0.0 exampleSetFlag: true exampleSetFlag: false MfaRuleListResponseEntity: title: MfaRuleListResponseEntity required: - response - version type: object properties: response: type: array example: '[{"mfaConnectionName":"Connection Name","mfaResultAction":"ACCEPT","mfaFailAction":"REJECT","rule":{"condition":{"conditionType":"ConditionAttributes","isNegate":false,"dictionaryName":"Network Access","attributeName":"Device IP Address","operator":"ipEquals","attributeValue":"10.0.10.0"},"default":false,"hitCounts":2,"id":"d82952cb-b901-4b09-b363-5ebf39bdbaf9","name":"MyRuleName_1","rank":1,"state":"enabled"},"link":{"href":"https://{{ISE_IP}}/api/v1/policy/{{protocol}}/policy-set/{{policy-id}}/mfa/d82952cb-b901-4b09-b363-5ebf39bdbaaa","rel":"self","type":"application/json"}}]' exampleSetFlag: true items: $ref: '#/components/schemas/RuleMfa' exampleSetFlag: false version: type: string example: 1.0.0 exampleSetFlag: true exampleSetFlag: false MessageResponseEntity: title: MessageResponseEntity required: - message type: object properties: message: type: string example: Success exampleSetFlag: true description: Response object containing success message exampleSetFlag: false IdResponseEntity: title: IdResponseEntity required: - id type: object properties: id: type: string format: uuid example: 07da6fd8-5abc-4dc4-bcec-df309dbf4d17 exampleSetFlag: true description: response object containing object ID exampleSetFlag: false Error: title: Error type: object properties: code: type: string example: '400' exampleSetFlag: true message: type: string example: Bad Request exampleSetFlag: true exampleSetFlag: false Condition: title: Condition required: - conditionType type: object properties: conditionType: type: string description: example: ConditionAttributes exampleSetFlag: true enum: - ConditionAndBlock - ConditionAttributes - ConditionOrBlock - ConditionReference - LibraryConditionAndBlock - LibraryConditionAttributes - LibraryConditionOrBlock - TimeAndDateCondition isNegate: type: boolean description: Indicates whereas this condition is in negate mode example: false exampleSetFlag: true link: $ref: '#/components/schemas/Link' exampleSetFlag: true description: exampleSetFlag: false RuleMfa: title: RuleMfa type: object properties: link: $ref: '#/components/schemas/Link' exampleSetFlag: true mfaConnectionName: type: string description: MFA Connection name for MFA example: api-XXXXXXXX.duosecurity.com exampleSetFlag: true mfaFailAction: type: string description: Action to perform when MFA fails example: REJECT exampleSetFlag: true mfaResultAction: type: string description: Action to perform when MFA is successful example: ACCEPT exampleSetFlag: true rule: $ref: '#/components/schemas/RuleCommon' exampleSetFlag: true description: Rule for MFA in Network Access/Device Admin exampleSetFlag: false securitySchemes: BasicAuth: type: http description: Basic authorization scheme: basic