{ "item": [ { "name": "mtoapi", "description": "", "item": [ { "name": "tenants", "description": "", "item": [ { "name": "TenantPicker", "description": "", "item": [ { "id": "fe723a16-f7a4-40d9-8455-b7ab04c4ffee", "name": "Get MTO tenant picker", "request": { "name": "Get MTO tenant picker", "description": { "content": "Retrieve the tenant picker payload used across the Defender multi-tenant management portal. Confirmed in live traffic from the MTO homepage, incidents, hunting, identity inventory, and administration pages.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "tenants", "TenantPicker" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "2b18294f-d84e-45a7-907f-00e6ac76d615", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", "TenantPicker" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"tenantInfoList\": [\n {\n \"selected\": true,\n \"lostAccess\": false,\n \"name\": \"string\",\n \"tenantId\": \"d8a10477-3941-83a4-a026-73fc333eaad9\",\n \"tenantAadEnvironment\": 2188,\n \"addedOn\": \"1963-11-18T18:48:45.620Z\"\n },\n {\n \"selected\": false,\n \"lostAccess\": false,\n \"name\": \"string\",\n \"tenantId\": \"9899ae72-1672-7ea9-1cdd-bbff1903f353\",\n \"tenantAadEnvironment\": 8222,\n \"addedOn\": \"2021-08-03T01:13:38.303Z\"\n }\n ],\n \"responseTypes\": {\n \"key_0\": \"string\"\n }\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "c0fbde3d-2a88-4a7b-96d7-fa9056c68310", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", "TenantPicker" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "f5d07fd9-a942-4a94-898e-9fefd2e5165c", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", "TenantPicker" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "915d9f97-ba1e-46e4-a25c-98a143631eae", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", "TenantPicker" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] }, { "name": "{TenantId}", "description": "", "item": [ { "name": "workloadStatus", "description": "", "item": [ { "id": "f68eef02-8ba3-4a36-92ee-013b86f1ab7e", "name": "Get tenant workload status", "request": { "name": "Get tenant workload status", "description": { "content": "Retrieve the workload status for a specific managed tenant, including the activation status of each Defender XDR workload.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "tenants", ":TenantId", "workloadStatus" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId", "disabled": false, "description": { "content": "(Required) The unique identifier of the tenant.", "type": "text/plain" } } ] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "7192023e-1ea2-49d4-aadd-2fa0d9a31343", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "workloadStatus" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"tenantId\": \"62ac7d66-3653-c488-d159-9f10f3834225\",\n \"workloads\": [\n {\n \"workloadName\": \"string\",\n \"isActivated\": false,\n \"lastUpdated\": \"1950-11-19T09:56:53.513Z\"\n },\n {\n \"workloadName\": \"string\",\n \"isActivated\": true,\n \"lastUpdated\": \"2022-08-29T16:40:32.517Z\"\n }\n ]\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "0f189168-d900-4f43-b6b6-2c3019056511", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "workloadStatus" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "900e8e21-b055-4517-9c93-862ea58955ab", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "workloadStatus" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "b15f961c-f685-4573-ac2c-f0c39b1ecc78", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "workloadStatus" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] }, { "name": "huntingQueries", "description": "", "item": [ { "name": "run", "description": "", "item": [ { "id": "6b5c7d3a-5462-48fd-845d-bf4af40e6457", "name": "Run cross-tenant hunting query", "request": { "name": "Run cross-tenant hunting query", "description": { "content": "Execute an advanced hunting query against a specific managed tenant. Allows cross-tenant threat hunting from the multi-tenant management view.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "tenants", ":TenantId", "huntingQueries", "run" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId", "disabled": false, "description": { "content": "(Required) The unique identifier of the target tenant.", "type": "text/plain" } } ] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"query\": \"string\",\n \"timespan\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "auth": null }, "response": [ { "id": "664b8697-b1ab-4490-85a5-6d19a63c11eb", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "huntingQueries", "run" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the target tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"query\": \"string\",\n \"timespan\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "1ada15c1-e32d-41af-a1fa-2765cf7a9bfd", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "huntingQueries", "run" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the target tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"query\": \"string\",\n \"timespan\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "96a1adbe-6f11-4582-bc52-f967bf8147c7", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "huntingQueries", "run" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the target tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"query\": \"string\",\n \"timespan\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "1bd20800-2207-4c2d-adc9-7e39e3e78443", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "tenants", ":TenantId", "huntingQueries", "run" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the target tenant.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TenantId" } ] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"query\": \"string\",\n \"timespan\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] } ] }, { "name": "recentItems", "description": "", "item": [ { "id": "0ee29511-a55c-4b05-980f-0a4303285beb", "name": "Get recent items", "request": { "name": "Get recent items", "description": { "content": "Retrieve recently accessed items in the Defender XDR portal for the current user. Used to populate the recent items list in the portal navigation.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "recentItems" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "99ad1b5d-5ebd-4e26-a8ce-e62bc6db2ba0", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "recentItems" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "[]", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "786083b0-982c-40f5-80fa-3042197dedd9", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "recentItems" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "0d3d6cce-d3da-4a57-ab5e-7dfec2cc1f2e", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "recentItems" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "4f1cf580-1385-44c5-b45a-5b8b822fab81", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "recentItems" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] }, { "name": "tenantGroups", "description": "", "item": [ { "id": "e68fe7e4-d879-4cdf-8179-fcdfe3577d14", "name": "List tenant groups", "request": { "name": "List tenant groups", "description": { "content": "Retrieve tenant groups available in the MTO portal. Confirmed in live traffic from the Tenant groups page.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "tenantGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "5eb2a293-f4d9-4966-8df9-babac3c41d8b", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "[\n {\n \"entityType\": \"string\",\n \"name\": \"string\",\n \"tenantGroupId\": \"de0a9928-9d58-f389-a856-74bb47453645\",\n \"userId\": \"084807fc-1e5a-cdfd-4dd6-743195e826c4\",\n \"type\": 3820,\n \"description\": \"string\",\n \"allTenantsCount\": 1662,\n \"exposedTargetTenantsInfo\": [\n {\n \"name\": \"string\",\n \"tenantId\": \"d470a37f-703d-dece-9675-d6f282f8f525\",\n \"tenantAadEnvironment\": 8875,\n \"addedOn\": \"1973-05-07T04:25:11.646Z\"\n },\n {\n \"name\": \"string\",\n \"tenantId\": \"dbd84cd0-7bc3-1617-5bfa-70f56ccb4bd0\",\n \"tenantAadEnvironment\": 7213,\n \"addedOn\": \"1966-02-08T21:28:41.327Z\"\n }\n ],\n \"creationTime\": \"2009-10-27T04:56:31.652Z\",\n \"lastUpdated\": \"2011-11-22T15:11:31.852Z\",\n \"lastUpdatedByUpn\": \"string\",\n \"id\": \"string\",\n \"tenantId\": \"e9748dbb-1d92-f4ff-e584-366ec56b6210\",\n \"_etag\": \"string\",\n \"ttl\": 4638\n },\n {\n \"entityType\": \"string\",\n \"name\": \"string\",\n \"tenantGroupId\": \"bf7248b1-6fed-996e-a2c6-684db1903824\",\n \"userId\": \"49c555a6-88f2-2cae-f171-9c22848904eb\",\n \"type\": 9642,\n \"description\": \"string\",\n \"allTenantsCount\": 1145,\n \"exposedTargetTenantsInfo\": [\n {\n \"name\": \"string\",\n \"tenantId\": \"cecb4087-7916-1fcc-93d9-d490aa88fdb0\",\n \"tenantAadEnvironment\": 9622,\n \"addedOn\": \"1975-02-16T09:33:23.345Z\"\n },\n {\n \"name\": \"string\",\n \"tenantId\": \"b35cf8a4-9c8a-6003-c655-3a2789aa0a75\",\n \"tenantAadEnvironment\": 3912,\n \"addedOn\": \"2010-02-22T03:50:25.809Z\"\n }\n ],\n \"creationTime\": \"1999-04-08T14:49:36.437Z\",\n \"lastUpdated\": \"1983-05-11T16:04:22.731Z\",\n \"lastUpdatedByUpn\": \"string\",\n \"id\": \"string\",\n \"tenantId\": \"24c4e35d-9044-5b35-bd37-13cbf7787351\",\n \"_etag\": \"string\",\n \"ttl\": 2367\n }\n]", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "83821201-7a76-4e8a-a2f3-2b10fb427eed", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "d80e28d7-a747-45b7-a5ec-aa2517a13e1f", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "cd8dbea4-beaf-4273-b406-73d1f6ca098b", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } }, { "name": "effective", "description": "", "item": [ { "id": "04004d76-b021-46f1-b3a1-004ee07e5e32", "name": "Get effective tenant group", "request": { "name": "Get effective tenant group", "description": { "content": "Retrieve the effective tenant group resolved for the signed-in user. Confirmed in live traffic across the MTO homepage, incidents, hunting, cases, identity inventory, content distribution, tenant groups, and unified RBAC pages.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "tenantGroups", "effective", "" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "6239a1a8-88f0-4b38-9d88-6f1442120275", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups", "effective", "" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"entityType\": \"TenantGroup\",\n \"name\": \"Managed tenants\",\n \"tenantGroupId\": \"00000000-0000-0000-0000-000000000001\",\n \"tenantId\": \"00000000-0000-0000-0000-000000000002\",\n \"type\": 0,\n \"description\": \"Effective tenant selection\",\n \"allTenantsCount\": 1,\n \"exposedTargetTenantsInfo\": [],\n \"creationTime\": \"2026-01-01T00:00:00Z\",\n \"lastUpdated\": \"2026-01-01T00:00:00Z\",\n \"lastUpdatedByUpn\": null,\n \"_etag\": \"sanitized-etag\",\n \"ttl\": 0\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "53c02fae-e18d-43b8-8daf-2b7fc1df605d", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups", "effective", "" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "0816d75e-d4e3-45a2-8e8d-f59c17d5d143", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups", "effective", "" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "c59bf3ce-a286-4d2d-b74b-daf4d0b8a726", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "tenantGroups", "effective", "" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] }, { "name": "assignments", "description": "", "item": [ { "id": "3f7d8e11-c396-4c87-a309-bdba5ca4f565", "name": "List content distribution assignments", "request": { "name": "List content distribution assignments", "description": { "content": "Retrieve content distribution assignments from the MTO Content distribution page, including target tenants, synced templates, variable maps, and per-target sync status.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "assignments" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "1d44c0f7-4e8d-49af-b6f6-b7ea280ad652", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "assignments" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"items\": [\n {\n \"eTag\": \"string\",\n \"id\": \"string\",\n \"name\": \"string\",\n \"description\": \"string\",\n \"createdOn\": \"1973-10-01T04:12:46.930Z\",\n \"createdBy\": \"string\",\n \"lastSyncedOn\": \"1984-11-11T04:51:11.276Z\",\n \"lastSyncedBy\": \"string\",\n \"targetTenantIds\": [\n \"d064d2c4-255d-0ef4-9a3b-98db0da723d7\",\n \"342fe74f-30f1-119f-3de2-06dbeae9e7ec\"\n ],\n \"templates\": [\n {\n \"id\": \"string\",\n \"type\": \"string\",\n \"name\": \"string\"\n },\n {\n \"id\": \"string\",\n \"type\": \"string\",\n \"name\": \"string\"\n }\n ],\n \"variables\": {\n \"key_0\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n }\n },\n \"templateVariables\": {\n \"key_0\": {\n \"key_0\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"key_1\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n }\n },\n \"key_1\": {\n \"key_0\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ],\n \"key_2\": [\n \"string\",\n \"string\"\n ]\n },\n \"key_1\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n },\n \"key_2\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n }\n },\n \"key_2\": {\n \"key_0\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"key_1\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n }\n }\n },\n \"syncUnitStatuses\": [\n {\n \"assignmentId\": \"string\",\n \"templateId\": \"string\",\n \"templateName\": \"string\",\n \"contentType\": \"string\",\n \"sourceTenantId\": \"d2e0fcee-361d-7966-a04d-72ea6c66955b\",\n \"sourceWorkspaceMetadata\": {},\n \"targetTenantId\": \"1fd50f33-f942-adb9-339f-e585b0e1a63b\",\n \"lastSyncedOn\": \"1976-08-28T03:06:50.592Z\",\n \"lastSyncedBy\": \"string\",\n \"syncStatus\": \"string\",\n \"errorType\": \"string\",\n \"syncedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"expectedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ],\n \"key_2\": [\n \"string\",\n \"string\"\n ]\n },\n \"targetContentId\": \"string\",\n \"id\": \"string\"\n },\n {\n \"assignmentId\": \"string\",\n \"templateId\": \"string\",\n \"templateName\": \"string\",\n \"contentType\": \"string\",\n \"sourceTenantId\": \"89694fa7-e8a7-aed3-01ba-a752a0477d83\",\n \"sourceWorkspaceMetadata\": {},\n \"targetTenantId\": \"2657ed0e-408e-41b0-aee9-ad1355c24a5e\",\n \"lastSyncedOn\": \"2002-04-29T16:53:06.614Z\",\n \"lastSyncedBy\": \"string\",\n \"syncStatus\": \"string\",\n \"errorType\": \"string\",\n \"syncedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n },\n \"expectedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"targetContentId\": \"string\",\n \"id\": \"string\"\n }\n ],\n \"targetTenantIdsWithoutRelationship\": 3907,\n \"isVariablePerTemplate\": false\n },\n {\n \"eTag\": \"string\",\n \"id\": \"string\",\n \"name\": \"string\",\n \"description\": \"string\",\n \"createdOn\": \"1978-03-02T09:32:40.971Z\",\n \"createdBy\": \"string\",\n \"lastSyncedOn\": \"2002-03-18T19:47:52.774Z\",\n \"lastSyncedBy\": \"string\",\n \"targetTenantIds\": [\n \"b8b5da53-5976-cda1-5e5d-a6c7f3c8b5cc\",\n \"05edcf8f-4a14-eee5-1408-99da5dad3995\"\n ],\n \"templates\": [\n {\n \"id\": \"string\",\n \"type\": \"string\",\n \"name\": \"string\"\n },\n {\n \"id\": \"string\",\n \"type\": \"string\",\n \"name\": \"string\"\n }\n ],\n \"variables\": {\n \"key_0\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"key_1\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ],\n \"key_2\": [\n \"string\",\n \"string\"\n ]\n }\n },\n \"templateVariables\": {\n \"key_0\": {\n \"key_0\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"key_1\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ],\n \"key_2\": [\n \"string\",\n \"string\"\n ]\n }\n }\n },\n \"syncUnitStatuses\": [\n {\n \"assignmentId\": \"string\",\n \"templateId\": \"string\",\n \"templateName\": \"string\",\n \"contentType\": \"string\",\n \"sourceTenantId\": \"b3d09dfa-91c8-0391-0707-960f7cd76600\",\n \"sourceWorkspaceMetadata\": {},\n \"targetTenantId\": \"bbec958e-8ff0-e7c8-911e-95b29112de5b\",\n \"lastSyncedOn\": \"1964-06-24T12:16:46.763Z\",\n \"lastSyncedBy\": \"string\",\n \"syncStatus\": \"string\",\n \"errorType\": \"string\",\n \"syncedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ]\n },\n \"expectedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ],\n \"key_2\": [\n \"string\",\n \"string\"\n ],\n \"key_3\": [\n \"string\",\n \"string\"\n ],\n \"key_4\": [\n \"string\",\n \"string\"\n ]\n },\n \"targetContentId\": \"string\",\n \"id\": \"string\"\n },\n {\n \"assignmentId\": \"string\",\n \"templateId\": \"string\",\n \"templateName\": \"string\",\n \"contentType\": \"string\",\n \"sourceTenantId\": \"cbf04bb3-844d-4f66-3edf-c87a867c9c05\",\n \"sourceWorkspaceMetadata\": {},\n \"targetTenantId\": \"a2a917fc-8d74-05ba-fa00-aafb163e4fa8\",\n \"lastSyncedOn\": \"1981-08-31T03:13:06.345Z\",\n \"lastSyncedBy\": \"string\",\n \"syncStatus\": \"string\",\n \"errorType\": \"string\",\n \"syncedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n },\n \"expectedVariables\": {\n \"key_0\": [\n \"string\",\n \"string\"\n ],\n \"key_1\": [\n \"string\",\n \"string\"\n ]\n },\n \"targetContentId\": \"string\",\n \"id\": \"string\"\n }\n ],\n \"targetTenantIdsWithoutRelationship\": 7280,\n \"isVariablePerTemplate\": false\n }\n ]\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "c6e84b03-230b-42e7-b726-4831c7c84c22", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "assignments" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "74abfc9c-dbc0-48a7-b8b1-013b5388f360", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "assignments" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "2ac48db1-2bfc-43da-a476-979c5a87e4a6", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "assignments" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] }, { "name": "mtp", "description": "", "item": [ { "name": "sccManagement", "description": "", "item": [ { "name": "mgmt", "description": "", "item": [ { "name": "TenantContext", "description": "", "item": [ { "id": "3eba3099-5d1c-48d6-83cd-cbec27d33217", "name": "Get MTO tenant context", "request": { "name": "Get MTO tenant context", "description": { "content": "Retrieve the multi-tenant-wrapped Defender tenant bootstrap used across the MTO portal. The response includes the selected tenant context plus per-tenant execution metadata for the current MTO selection.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "sccManagement", "mgmt", "TenantContext" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether to fetch real-time context instead of cached data.", "type": "text/plain" }, "key": "realTime", "value": "false" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "136dfcc6-be41-4249-9bdc-8e64d20384bc", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "sccManagement", "mgmt", "TenantContext" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether to fetch real-time context instead of cached data.", "type": "text/plain" }, "key": "realTime", "value": "false" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {\n \"featureGroups\": [],\n \"featuresNames\": [],\n \"tenantsData\": {}\n },\n \"metadata\": {\n \"completedTenants\": [],\n \"responses\": {},\n \"isResultBase64Encoded\": false\n },\n \"isMtoResponse\": true\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "df9ddbd8-ee5a-4db2-982e-a3fb8f9fadb1", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "sccManagement", "mgmt", "TenantContext" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether to fetch real-time context instead of cached data.", "type": "text/plain" }, "key": "realTime", "value": "false" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "6c5e1e7a-7364-4705-a12a-98d53be19fa3", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "sccManagement", "mgmt", "TenantContext" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether to fetch real-time context instead of cached data.", "type": "text/plain" }, "key": "realTime", "value": "false" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "bb5a371a-4a74-4f0d-92cf-c4a4f89e49b6", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "sccManagement", "mgmt", "TenantContext" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether to fetch real-time context instead of cached data.", "type": "text/plain" }, "key": "realTime", "value": "false" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] }, { "name": "huntingService", "description": "", "item": [ { "name": "queries", "description": "", "item": [ { "id": "72e82188-a4f5-4543-bd22-d6be7381d2ca", "name": "List MTO hunting queries", "request": { "name": "List MTO hunting queries", "description": { "content": "Retrieve saved advanced hunting queries in the MTO portal. Confirmed in live traffic from the MTO Advanced hunting page with `type=user`, `type=shared`, and `type=scheduled` query variants.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "huntingService", "queries", "" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Query collection type to retrieve. (This can only be one of user,shared,scheduled)", "type": "text/plain" }, "key": "type", "value": "user" }, { "disabled": false, "description": { "content": "Tenant IDs to scope the query collection to.", "type": "text/plain" }, "key": "tenantIds[]", "value": "c7bdf1cb-e7f4-3095-991a-d1061c6a237b" }, { "disabled": false, "description": { "content": "Tenant IDs to scope the query collection to.", "type": "text/plain" }, "key": "tenantIds[]", "value": "c7bdf1cb-e7f4-3095-991a-d1061c6a237b" }, { "disabled": false, "description": { "content": "Whether to include USX queries in the result set.", "type": "text/plain" }, "key": "includeUsxQueries", "value": "false" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "7e9261ee-cebb-4217-925a-a9adba71be6f", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "huntingService", "queries", "" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Query collection type to retrieve. (This can only be one of user,shared,scheduled)", "type": "text/plain" }, "key": "type", "value": "user" }, { "disabled": false, "description": { "content": "Tenant IDs to scope the query collection to.", "type": "text/plain" }, "key": "tenantIds[]", "value": "c7bdf1cb-e7f4-3095-991a-d1061c6a237b" }, { "disabled": false, "description": { "content": "Whether to include USX queries in the result set.", "type": "text/plain" }, "key": "includeUsxQueries", "value": "false" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "f4663695-13ab-489e-89e8-9c2790890feb", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "huntingService", "queries", "" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Query collection type to retrieve. (This can only be one of user,shared,scheduled)", "type": "text/plain" }, "key": "type", "value": "user" }, { "disabled": false, "description": { "content": "Tenant IDs to scope the query collection to.", "type": "text/plain" }, "key": "tenantIds[]", "value": "c7bdf1cb-e7f4-3095-991a-d1061c6a237b" }, { "disabled": false, "description": { "content": "Whether to include USX queries in the result set.", "type": "text/plain" }, "key": "includeUsxQueries", "value": "false" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "6b2274fd-b689-4013-8c9d-5dcb97972bda", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "huntingService", "queries", "" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Query collection type to retrieve. (This can only be one of user,shared,scheduled)", "type": "text/plain" }, "key": "type", "value": "user" }, { "disabled": false, "description": { "content": "Tenant IDs to scope the query collection to.", "type": "text/plain" }, "key": "tenantIds[]", "value": "c7bdf1cb-e7f4-3095-991a-d1061c6a237b" }, { "disabled": false, "description": { "content": "Whether to include USX queries in the result set.", "type": "text/plain" }, "key": "includeUsxQueries", "value": "false" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "9916e286-d26b-4141-b6b4-b78bb6b6fe0f", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "huntingService", "queries", "" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Query collection type to retrieve. (This can only be one of user,shared,scheduled)", "type": "text/plain" }, "key": "type", "value": "user" }, { "disabled": false, "description": { "content": "Tenant IDs to scope the query collection to.", "type": "text/plain" }, "key": "tenantIds[]", "value": "c7bdf1cb-e7f4-3095-991a-d1061c6a237b" }, { "disabled": false, "description": { "content": "Whether to include USX queries in the result set.", "type": "text/plain" }, "key": "includeUsxQueries", "value": "false" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] }, { "name": "userExposedRbacGroups", "description": "", "item": [ { "name": "UserExposedRbacGroups", "description": "", "item": [ { "id": "8b332196-b839-4706-ba86-a189b1e9cc91", "name": "Get MTO hunting RBAC groups", "request": { "name": "Get MTO hunting RBAC groups", "description": { "content": "Retrieve the RBAC groups exposed to the current user for the MTO Advanced hunting page. Confirmed in live traffic from `mto.security.microsoft.com`.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "userExposedRbacGroups", "UserExposedRbacGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "ba530afc-1d71-4327-84b1-850f4cac32f3", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "userExposedRbacGroups", "UserExposedRbacGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "f13e2b17-2ea2-4017-b85c-6528e899f442", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "userExposedRbacGroups", "UserExposedRbacGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "004458d6-6dfa-4f29-a4aa-b7794b12659a", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "userExposedRbacGroups", "UserExposedRbacGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "e89e28f5-c7b8-45ec-beaa-70f3c42e528e", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "userExposedRbacGroups", "UserExposedRbacGroups" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] }, { "name": "CaseManagement", "description": "", "item": [ { "name": "be", "description": "", "item": [ { "name": "cases", "description": "", "item": [ { "id": "3e7061dc-f95a-4358-81f5-e584dbd5a7c6", "name": "List MTO cases", "request": { "name": "List MTO cases", "description": { "content": "Retrieve case-management records through the MTO wrapper. Confirmed in live traffic from the MTO Cases page.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "cases" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Optional OData sort expression for case rows.", "type": "text/plain" }, "key": "$orderby", "value": "string" }, { "disabled": false, "description": { "content": "Optional pagination cursor returned by prior MTO case reads.", "type": "text/plain" }, "key": "paginationGuid", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "afd7145f-927f-4856-8c65-0a0edb52555a", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "cases" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Optional OData sort expression for case rows.", "type": "text/plain" }, "key": "$orderby", "value": "string" }, { "disabled": false, "description": { "content": "Optional pagination cursor returned by prior MTO case reads.", "type": "text/plain" }, "key": "paginationGuid", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {},\n \"metadata\": {\n \"responses\": {\n \"key_0\": [\n {\n \"latencyInMs\": 4832,\n \"status\": 5998,\n \"errorCode\": \"string\",\n \"retryCount\": 8041\n },\n {\n \"latencyInMs\": 8979,\n \"status\": 4869,\n \"errorCode\": \"string\",\n \"retryCount\": 8428\n }\n ],\n \"key_1\": [\n {\n \"latencyInMs\": 624,\n \"status\": 1654,\n \"errorCode\": \"string\",\n \"retryCount\": 718\n },\n {\n \"latencyInMs\": 9882,\n \"status\": 4668,\n \"errorCode\": \"string\",\n \"retryCount\": 8648\n }\n ],\n \"key_2\": [\n {\n \"latencyInMs\": 4843,\n \"status\": 6741,\n \"errorCode\": \"string\",\n \"retryCount\": 3294\n },\n {\n \"latencyInMs\": 4229,\n \"status\": 2068,\n \"errorCode\": \"string\",\n \"retryCount\": 4585\n }\n ]\n },\n \"paginationGuid\": \"a86d0d2d-001d-1dea-56ea-e1ece41d7ab0\",\n \"chosenItems\": [\n {\n \"identifier\": \"5d3bddff-5a2d-4df0-93d8-e1f4d986e3c4\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 2083,\n \"isLastItemInPage\": true,\n \"nextPagePointer\": \"string\"\n },\n {\n \"identifier\": \"463076db-8223-a7d3-39ba-6983f3969698\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 5472,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n }\n ],\n \"completedTenants\": [\n \"18548a51-6f6d-bd44-2f5a-3c41effe92dc\",\n \"1c034ec0-5777-13d7-0036-1b389c14e854\"\n ],\n \"isResultBase64Encoded\": false\n },\n \"isMtoResponse\": false\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "03b1dfec-128a-437d-892b-43f5f83ccd03", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "cases" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Optional OData sort expression for case rows.", "type": "text/plain" }, "key": "$orderby", "value": "string" }, { "disabled": false, "description": { "content": "Optional pagination cursor returned by prior MTO case reads.", "type": "text/plain" }, "key": "paginationGuid", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "2f0be637-dc75-470e-bf91-21d06bace943", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "cases" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Optional OData sort expression for case rows.", "type": "text/plain" }, "key": "$orderby", "value": "string" }, { "disabled": false, "description": { "content": "Optional pagination cursor returned by prior MTO case reads.", "type": "text/plain" }, "key": "paginationGuid", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "05f2fd14-7401-446e-a8a3-93a3406b9787", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "cases" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Optional OData sort expression for case rows.", "type": "text/plain" }, "key": "$orderby", "value": "string" }, { "disabled": false, "description": { "content": "Optional pagination cursor returned by prior MTO case reads.", "type": "text/plain" }, "key": "paginationGuid", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] }, { "name": "templates", "description": "", "item": [ { "name": "{TemplateId}", "description": "", "item": [ { "id": "bb1ba4ea-a6e2-4d15-9cf8-b5290a5a9e8c", "name": "Get MTO case template", "request": { "name": "Get MTO case template", "description": { "content": "Retrieve a case template through the MTO wrapper. Confirmed in live traffic from the MTO Cases page using the default all-zero template ID.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "templates", ":TemplateId" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TemplateId", "disabled": false, "description": { "content": "(Required) The unique identifier of the case template.", "type": "text/plain" } } ] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "9204c2a8-b961-4456-b286-d9adedbe9e7c", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "templates", ":TemplateId" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the case template.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TemplateId" } ] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {\n \"displayName\": \"string\",\n \"templateType\": \"string\",\n \"description\": \"string\",\n \"defaultStatusId\": \"2ff99657-c063-399e-b7c5-abb8a6c1e566\",\n \"topLevelStatuses\": [\n {\n \"statusId\": \"30abef54-0e9c-9ab3-5bee-fef5cac49662\",\n \"displayName\": \"string\",\n \"tenantId\": \"16a94af0-4dea-4780-05d6-09e7c3c2a13f\"\n },\n {\n \"statusId\": \"35c36601-05be-6ac1-e3b7-efa0421ebcc9\",\n \"displayName\": \"string\",\n \"tenantId\": \"f4d2ca29-0e21-4c86-51f4-82b9b164cac9\"\n }\n ],\n \"statusSortOrder\": {\n \"key_0\": 4932\n },\n \"uiConfig\": {},\n \"templateFields\": {},\n \"id\": \"8e2d51a6-293d-089a-5d5e-85540b64d686\",\n \"createdDateTime\": \"1957-06-24T14:53:58.197Z\",\n \"createdBy\": \"string\",\n \"lastModifiedDateTime\": \"2013-09-09T10:22:15.689Z\",\n \"lastModifiedBy\": \"string\",\n \"eTag\": \"string\",\n \"tenantId\": \"410a5e08-81ff-535d-e26b-7e982f045728\"\n },\n \"metadata\": {\n \"responses\": {\n \"key_0\": [\n {\n \"latencyInMs\": 1288,\n \"status\": 1477,\n \"errorCode\": \"string\",\n \"retryCount\": 3974\n },\n {\n \"latencyInMs\": 1026,\n \"status\": 180,\n \"errorCode\": \"string\",\n \"retryCount\": 6352\n }\n ]\n },\n \"paginationGuid\": \"494e2e07-04a0-3be8-2282-3928a82c98c4\",\n \"chosenItems\": [\n {\n \"identifier\": \"67b287f7-77a5-b838-edd8-51d1be0d0b65\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 977,\n \"isLastItemInPage\": true,\n \"nextPagePointer\": \"string\"\n },\n {\n \"identifier\": \"658390f4-25bc-a292-590e-11bacf35ecf1\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 5324,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n }\n ],\n \"completedTenants\": [\n \"c16a975e-bc1c-e269-f67c-3fe7f662aa58\",\n \"ef60f4f9-652f-04b1-8ef7-b75bfae64502\"\n ],\n \"isResultBase64Encoded\": true\n },\n \"isMtoResponse\": false\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "86bdf737-fa2e-4caf-a2f8-73646d9085c4", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "templates", ":TemplateId" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the case template.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TemplateId" } ] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "9e8b0df3-a06e-4d9a-9c48-3f2928fe5468", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "templates", ":TemplateId" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the case template.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TemplateId" } ] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "f1405e29-cb71-4450-85ec-ae5dbc573957", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "CaseManagement", "be", "templates", ":TemplateId" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [ { "disabled": false, "description": { "content": "(Required) The unique identifier of the case template.", "type": "text/plain" }, "type": "any", "value": "09ab8738-fe58-a22e-cbfe-c8bc1b38bbf3", "key": "TemplateId" } ] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] } ] }, { "name": "incidentDashboard", "description": "", "item": [ { "name": "Dashboard", "description": "", "item": [ { "name": "ActiveIncidentsSummary", "description": "", "item": [ { "id": "1f238626-b96d-41d4-8ff9-eabdef1e903c", "name": "Get MTO active incident summary", "request": { "name": "Get MTO active incident summary", "description": { "content": "Retrieve the cross-tenant incident count, trend series, and leading incidents rendered on the MTO landing dashboard. This is the MTO wrapper for the native Defender incident-dashboard read; the wrapper adds result and execution-metadata envelopes for the current multi-tenant scope.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "incidentDashboard", "Dashboard", "ActiveIncidentsSummary" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether the wrapper may return cached dashboard data.", "type": "text/plain" }, "key": "readFromCache", "value": "true" }, { "disabled": false, "description": { "content": "Maximum number of leading incidents to include.", "type": "text/plain" }, "key": "latestIncidentsCount", "value": "7798" }, { "disabled": false, "description": { "content": "Trend lookback window in days, preserving the portal's observed casing.", "type": "text/plain" }, "key": "lookbackIndays", "value": "8179" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "426c5890-938e-4fdd-a1ba-1574252256a8", "name": "MTO-wrapped incident dashboard summary.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "incidentDashboard", "Dashboard", "ActiveIncidentsSummary" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether the wrapper may return cached dashboard data.", "type": "text/plain" }, "key": "readFromCache", "value": "true" }, { "disabled": false, "description": { "content": "Maximum number of leading incidents to include.", "type": "text/plain" }, "key": "latestIncidentsCount", "value": "7798" }, { "disabled": false, "description": { "content": "Trend lookback window in days, preserving the portal's observed casing.", "type": "text/plain" }, "key": "lookbackIndays", "value": "8179" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {\n \"activeIncidentCount\": 2,\n \"alertsTrend\": [\n {\n \"TimeUtc\": \"2026-01-01T00:00:00Z\",\n \"Count\": 1\n }\n ],\n \"incidentsTrend\": [\n {\n \"TimeUtc\": \"2026-01-01T00:00:00Z\",\n \"Count\": 1\n }\n ],\n \"topIncidents\": []\n },\n \"metadata\": {\n \"completedTenants\": [],\n \"responses\": {},\n \"isResultBase64Encoded\": false\n },\n \"isMtoResponse\": true\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "5da1e14d-d4f9-4397-ade1-57643e7a0a1e", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "incidentDashboard", "Dashboard", "ActiveIncidentsSummary" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether the wrapper may return cached dashboard data.", "type": "text/plain" }, "key": "readFromCache", "value": "true" }, { "disabled": false, "description": { "content": "Maximum number of leading incidents to include.", "type": "text/plain" }, "key": "latestIncidentsCount", "value": "7798" }, { "disabled": false, "description": { "content": "Trend lookback window in days, preserving the portal's observed casing.", "type": "text/plain" }, "key": "lookbackIndays", "value": "8179" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "8b1e7fd6-ef87-4be7-b43c-02183389f1f7", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "incidentDashboard", "Dashboard", "ActiveIncidentsSummary" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether the wrapper may return cached dashboard data.", "type": "text/plain" }, "key": "readFromCache", "value": "true" }, { "disabled": false, "description": { "content": "Maximum number of leading incidents to include.", "type": "text/plain" }, "key": "latestIncidentsCount", "value": "7798" }, { "disabled": false, "description": { "content": "Trend lookback window in days, preserving the portal's observed casing.", "type": "text/plain" }, "key": "lookbackIndays", "value": "8179" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "ae3f4663-6035-43d2-843a-bcf75bbe7abf", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "incidentDashboard", "Dashboard", "ActiveIncidentsSummary" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Whether the wrapper may return cached dashboard data.", "type": "text/plain" }, "key": "readFromCache", "value": "true" }, { "disabled": false, "description": { "content": "Maximum number of leading incidents to include.", "type": "text/plain" }, "key": "latestIncidentsCount", "value": "7798" }, { "disabled": false, "description": { "content": "Trend lookback window in days, preserving the portal's observed casing.", "type": "text/plain" }, "key": "lookbackIndays", "value": "8179" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] }, { "name": "rbacManagementApi", "description": "", "item": [ { "name": "rbac", "description": "", "item": [ { "name": "machine_groups", "description": "", "item": [ { "id": "cd3a31d8-e3dd-4eef-b719-febe2b908776", "name": "List MTO machine groups", "request": { "name": "List MTO machine groups", "description": { "content": "Retrieve Defender for Endpoint RBAC machine groups through the MTO wrapper. The native machine-group semantics are shared with Defender XDR; this operation documents the cross-tenant result and metadata envelope.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mtp", "rbacManagementApi", "rbac", "machine_groups" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Include related Entra group names when available.", "type": "text/plain" }, "key": "addAadGroupNames", "value": "true" }, { "disabled": false, "description": { "content": "Include machine counts for each returned group.", "type": "text/plain" }, "key": "addMachineGroupCount", "value": "true" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "6644171e-a3e5-4201-b1b8-a38018d206cb", "name": "MTO-wrapped machine-group inventory.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "rbacManagementApi", "rbac", "machine_groups" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Include related Entra group names when available.", "type": "text/plain" }, "key": "addAadGroupNames", "value": "true" }, { "disabled": false, "description": { "content": "Include machine counts for each returned group.", "type": "text/plain" }, "key": "addMachineGroupCount", "value": "true" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {\n \"items\": [\n {\n \"MachineGroupId\": 1,\n \"Name\": \"Default\",\n \"Description\": \"Default machine group\",\n \"Priority\": 1,\n \"MachineCount\": 0,\n \"IsUnassignedMachineGroup\": true,\n \"AutoRemediationLevel\": 0\n }\n ]\n },\n \"metadata\": {\n \"completedTenants\": [],\n \"responses\": {},\n \"isResultBase64Encoded\": false\n },\n \"isMtoResponse\": true\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "927449ae-f212-4be7-b59e-47adfb86ffa9", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "rbacManagementApi", "rbac", "machine_groups" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Include related Entra group names when available.", "type": "text/plain" }, "key": "addAadGroupNames", "value": "true" }, { "disabled": false, "description": { "content": "Include machine counts for each returned group.", "type": "text/plain" }, "key": "addMachineGroupCount", "value": "true" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "c4acf4b3-f803-428f-af83-c64dc9cb2847", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "rbacManagementApi", "rbac", "machine_groups" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Include related Entra group names when available.", "type": "text/plain" }, "key": "addAadGroupNames", "value": "true" }, { "disabled": false, "description": { "content": "Include machine counts for each returned group.", "type": "text/plain" }, "key": "addMachineGroupCount", "value": "true" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "f2919091-8859-496a-a880-2f300e9a44c3", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mtp", "rbacManagementApi", "rbac", "machine_groups" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "Include related Entra group names when available.", "type": "text/plain" }, "key": "addAadGroupNames", "value": "true" }, { "disabled": false, "description": { "content": "Include machine counts for each returned group.", "type": "text/plain" }, "key": "addMachineGroupCount", "value": "true" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] } ] }, { "name": "mdi", "description": "", "item": [ { "name": "identity", "description": "", "item": [ { "name": "userapiservice", "description": "", "item": [ { "name": "identities", "description": "", "item": [ { "id": "c19a4622-98aa-4555-ad67-ef14a7ed0681", "name": "List MTO identities", "request": { "name": "List MTO identities", "description": { "content": "Retrieve identities from the MTO Identity Inventory page with cross-tenant aggregation and MTO response metadata.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"PageSize\": 8272,\n \"Skip\": 5179,\n \"SortBy\": {},\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "auth": null }, "response": [ { "id": "de707484-700d-4904-a138-999b506a2a25", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"PageSize\": 8272,\n \"Skip\": 5179,\n \"SortBy\": {},\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {},\n \"metadata\": {\n \"responses\": {\n \"key_0\": [\n {\n \"latencyInMs\": 299,\n \"status\": 1812,\n \"errorCode\": \"string\",\n \"retryCount\": 8533\n },\n {\n \"latencyInMs\": 3160,\n \"status\": 8617,\n \"errorCode\": \"string\",\n \"retryCount\": 9456\n }\n ],\n \"key_1\": [\n {\n \"latencyInMs\": 9637,\n \"status\": 3724,\n \"errorCode\": \"string\",\n \"retryCount\": 2790\n },\n {\n \"latencyInMs\": 2175,\n \"status\": 9279,\n \"errorCode\": \"string\",\n \"retryCount\": 3144\n }\n ]\n },\n \"paginationGuid\": \"094acce4-19ef-f41a-ff56-7c77bf0aac21\",\n \"chosenItems\": [\n {\n \"identifier\": \"bcb059f9-5975-bc37-45bb-2577a3be2362\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 2759,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n },\n {\n \"identifier\": \"ba24b2ea-f018-4455-4cc4-cb4a172bb570\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 8353,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n }\n ],\n \"completedTenants\": [\n \"54915610-bd1c-d2bb-c154-7a5f4e6d2e5d\",\n \"1f4f940d-8f3a-3982-20dd-b0658a250502\"\n ],\n \"isResultBase64Encoded\": true\n },\n \"isMtoResponse\": true\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "82c90021-2866-4cc2-b3b5-a320de1e8c3f", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"PageSize\": 8272,\n \"Skip\": 5179,\n \"SortBy\": {},\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "a3592d1d-e035-4dd9-9ec7-4df0d7cccf8c", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"PageSize\": 8272,\n \"Skip\": 5179,\n \"SortBy\": {},\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "0a5d401c-c84a-492a-8c34-133dacf988f5", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"PageSize\": 8272,\n \"Skip\": 5179,\n \"SortBy\": {},\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } }, { "name": "aggregatedData", "description": "", "item": [ { "id": "0baa6cd0-db1b-4f4a-addb-80f388b5f696", "name": "Get MTO identities aggregated data", "request": { "name": "Get MTO identities aggregated data", "description": { "content": "Retrieve aggregate identity totals and facets for the MTO Identity Inventory page.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "aggregatedData" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "auth": null }, "response": [ { "id": "b135767d-ccd7-4975-9f7b-e1cc749f0b04", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "aggregatedData" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": {\n \"total\": 3509,\n \"disabled\": 1198,\n \"sensitive\": 4347,\n \"serviceAccounts\": 7452,\n \"criticalServiceAccounts\": 7975,\n \"criticalIdentities\": 9894,\n \"highlyPrivilegedIdentities\": 4047\n },\n \"metadata\": {\n \"responses\": {\n \"key_0\": [\n {\n \"latencyInMs\": 425,\n \"status\": 3850,\n \"errorCode\": \"string\",\n \"retryCount\": 5598\n },\n {\n \"latencyInMs\": 8030,\n \"status\": 4027,\n \"errorCode\": \"string\",\n \"retryCount\": 9299\n }\n ],\n \"key_1\": [\n {\n \"latencyInMs\": 5143,\n \"status\": 509,\n \"errorCode\": \"string\",\n \"retryCount\": 1682\n },\n {\n \"latencyInMs\": 2705,\n \"status\": 3354,\n \"errorCode\": \"string\",\n \"retryCount\": 1837\n }\n ]\n },\n \"paginationGuid\": \"8f40ea14-82c7-5295-7fd4-2aa5afa563ac\",\n \"chosenItems\": [\n {\n \"identifier\": \"35970975-d1d8-71a2-b710-460d40811fee\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 6191,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n },\n {\n \"identifier\": \"45ce1da4-302c-f9ae-0b63-d5f1678f5921\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 9000,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n }\n ],\n \"completedTenants\": [\n \"1dcb16e8-5b38-2c9d-e4b2-d21c37a15b02\",\n \"d8d8f60c-18ac-fba8-6070-a5f966cf390e\"\n ],\n \"isResultBase64Encoded\": false\n },\n \"isMtoResponse\": false\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "6b8eb128-5129-4639-a752-b648e6035268", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "aggregatedData" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "c1bded5d-8d47-4ee5-ada4-618dca3d78e7", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "aggregatedData" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "e37f89d7-23b9-4057-bfe0-b6f18506c980", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "aggregatedData" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] }, { "name": "count", "description": "", "item": [ { "id": "4576d9d5-9b96-4ae0-9aea-623b27760d72", "name": "Get MTO identities count", "request": { "name": "Get MTO identities count", "description": { "content": "Retrieve the total number of identities matching the supplied MTO filters.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "count" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "auth": null }, "response": [ { "id": "39a3c8c7-77bc-41c8-a43f-4cc51665ecab", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "count" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"result\": 3507,\n \"metadata\": {\n \"responses\": {\n \"key_0\": [\n {\n \"latencyInMs\": 7770,\n \"status\": 6484,\n \"errorCode\": \"string\",\n \"retryCount\": 1928\n },\n {\n \"latencyInMs\": 6649,\n \"status\": 3761,\n \"errorCode\": \"string\",\n \"retryCount\": 4538\n }\n ],\n \"key_1\": [\n {\n \"latencyInMs\": 1643,\n \"status\": 4079,\n \"errorCode\": \"string\",\n \"retryCount\": 1612\n },\n {\n \"latencyInMs\": 6836,\n \"status\": 2421,\n \"errorCode\": \"string\",\n \"retryCount\": 8544\n }\n ]\n },\n \"paginationGuid\": \"23254ada-4057-a987-d5ce-10df13215bf3\",\n \"chosenItems\": [\n {\n \"identifier\": \"b7a99f58-29ec-5e8e-9df2-3db2774fb75e\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 4636,\n \"isLastItemInPage\": true,\n \"nextPagePointer\": \"string\"\n },\n {\n \"identifier\": \"289e6ead-8a1e-62c8-7c69-dd8351ac6e92\",\n \"originalPagePointer\": \"string\",\n \"originalIndex\": 1043,\n \"isLastItemInPage\": false,\n \"nextPagePointer\": \"string\"\n }\n ],\n \"completedTenants\": [\n \"2f9922ec-076a-9bc0-fcee-b98ffc5d49d3\",\n \"66800f91-8342-590d-e94d-cc8f63cb6134\"\n ],\n \"isResultBase64Encoded\": false\n },\n \"isMtoResponse\": true\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "6830e2d9-1d2a-4b8f-868a-fc76e0ea02e8", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "count" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "a8bcdb9a-9d83-4835-bbfc-e1f33c16141f", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "count" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "c4084013-d4f8-4b5d-b5a4-11da417233f7", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "mdi", "identity", "userapiservice", "identities", "count" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Content-Type", "value": "application/json" } ], "method": "POST", "body": { "mode": "raw", "raw": "{\n \"Filters\": {},\n \"SearchText\": \"string\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } } }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] } ] } ] }, { "name": "cdssecuritycopilot", "description": "", "item": [ { "name": "trial", "description": "", "item": [ { "id": "c8aa720b-3e72-439e-9300-940fd0ae8b4b", "name": "Get MTO Security Copilot trial status", "request": { "name": "Get MTO Security Copilot trial status", "description": { "content": "Retrieve the Security Copilot trial status probe used by the MTO Advanced hunting and Custom detection pages. Live traffic in the current tenant returned a contextual `400 InvalidProxyPrefix` response.", "type": "text/plain" }, "url": { "path": [ "mtoapi", "cdssecuritycopilot", "trial" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "(Required) Requested access scope for the trial probe.", "type": "text/plain" }, "key": "scope", "value": "string" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "03dfd598-d573-4a6d-9f5a-34acefa5a984", "name": "OK", "originalRequest": { "url": { "path": [ "mtoapi", "cdssecuritycopilot", "trial" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "(Required) Requested access scope for the trial probe.", "type": "text/plain" }, "key": "scope", "value": "string" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "0788703d-5bc9-4d42-beae-61e03811250e", "name": "Contextual backend validation error returned by the current tenant.", "originalRequest": { "url": { "path": [ "mtoapi", "cdssecuritycopilot", "trial" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "(Required) Requested access scope for the trial probe.", "type": "text/plain" }, "key": "scope", "value": "string" } ], "variable": [] }, "header": [ { "key": "Accept", "value": "application/json" } ], "method": "GET", "body": {} }, "status": "Bad Request", "code": 400, "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "{\n \"Error\": \"string\"\n}", "cookie": [], "_postman_previewlanguage": "json" }, { "id": "29abf0f1-26b9-4026-85d0-32ae2afd958e", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtoapi", "cdssecuritycopilot", "trial" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "(Required) Requested access scope for the trial probe.", "type": "text/plain" }, "key": "scope", "value": "string" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "c8ecb879-e592-4052-a291-6447e7f6d744", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtoapi", "cdssecuritycopilot", "trial" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "(Required) Requested access scope for the trial probe.", "type": "text/plain" }, "key": "scope", "value": "string" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "2ef609f6-870b-4863-9fd5-ad4072798fc2", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtoapi", "cdssecuritycopilot", "trial" ], "host": [ "{{baseUrl}}" ], "query": [ { "disabled": false, "description": { "content": "(Required) Requested access scope for the trial probe.", "type": "text/plain" }, "key": "scope", "value": "string" } ], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] }, { "name": "mtp", "description": "", "item": [ { "name": "userPreferences", "description": "", "item": [ { "name": "api", "description": "", "item": [ { "name": "mgmt", "description": "", "item": [ { "name": "userpreferencesservice", "description": "", "item": [ { "name": "userPreference", "description": "", "item": [ { "name": "advanced_hunting_mto", "description": "", "item": [ { "id": "dfd12170-3353-4f20-b1c0-bbb8c9606fb0", "name": "Get MTO advanced hunting preferences", "request": { "name": "Get MTO advanced hunting preferences", "description": { "content": "Retrieve the serialized multi-tenant advanced hunting preference blob. Confirmed in live traffic from the MTO Advanced hunting and Custom detection pages.", "type": "text/plain" }, "url": { "path": [ "mtp", "userPreferences", "api", "mgmt", "userpreferencesservice", "userPreference", "advanced_hunting_mto" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "text/plain" } ], "method": "GET", "body": {}, "auth": null }, "response": [ { "id": "2854f994-63de-4270-bc88-12c1296de734", "name": "OK", "originalRequest": { "url": { "path": [ "mtp", "userPreferences", "api", "mgmt", "userpreferencesservice", "userPreference", "advanced_hunting_mto" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "header": [ { "key": "Accept", "value": "text/plain" } ], "method": "GET", "body": {} }, "status": "OK", "code": 200, "header": [ { "key": "Content-Type", "value": "text/plain" } ], "body": "{\"tabs\":{\"queryTabs\":[]}}", "cookie": [], "_postman_previewlanguage": "text" }, { "id": "c7dc2d66-c9e3-4632-80b7-70c341e31f3a", "name": "Authentication is missing, expired, or invalid for the Defender portal session.", "originalRequest": { "url": { "path": [ "mtp", "userPreferences", "api", "mgmt", "userpreferencesservice", "userPreference", "advanced_hunting_mto" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Unauthorized", "code": 401, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "2989bd4d-a3d5-4cc3-8e20-2bfbb43321bd", "name": "The signed-in operator does not have access to the requested tenant or workload.", "originalRequest": { "url": { "path": [ "mtp", "userPreferences", "api", "mgmt", "userpreferencesservice", "userPreference", "advanced_hunting_mto" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Forbidden", "code": 403, "header": [], "cookie": [], "_postman_previewlanguage": "text" }, { "id": "a89fa69a-8ff3-4a49-98b5-98bbcd8c4f89", "name": "The requested MTO resource or wrapped Defender resource was not found.", "originalRequest": { "url": { "path": [ "mtp", "userPreferences", "api", "mgmt", "userpreferencesservice", "userPreference", "advanced_hunting_mto" ], "host": [ "{{baseUrl}}" ], "query": [], "variable": [] }, "method": "GET", "body": {} }, "status": "Not Found", "code": 404, "header": [], "cookie": [], "_postman_previewlanguage": "text" } ], "event": [], "protocolProfileBehavior": { "disableBodyPruning": true } } ] } ] } ] } ] } ] } ] } ] } ], "auth": { "type": "apikey", "apikey": [ { "type": "any", "value": "sccauth", "key": "key" }, { "type": "any", "value": "{{apiKey}}", "key": "value" }, { "type": "any", "value": "header", "key": "in" } ] }, "event": [], "variable": [ { "key": "baseUrl", "value": "https://mto.security.microsoft.com/apiproxy" } ], "info": { "_postman_id": "cfe0ec84-de69-4088-b2f2-8a379ec416a8", "name": "Defender XDR (MTO)", "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json", "description": { "content": "Undocumented operations used by the Microsoft Defender XDR multi-tenant\norganization portal at `mto.security.microsoft.com`.\n\nThis is a portal-view specification. Many operations wrap native Defender\nXDR services beneath `/mtoapi/` so an operator can work across the tenants\navailable to their MTO scope. A route in this specification therefore does\nnot imply a separate backend implementation; it records the MTO transport,\nselection context, response envelope, and portal workflow that agents need\nto reproduce or troubleshoot the multi-tenant experience.\n\nNative `security.microsoft.com` operations remain in the Defender XDR spec.\nMTO-wrapped operations are kept here even when their result payload mirrors\na native Defender operation, avoiding duplicate ownership while preserving\nthe observable portal contract.\n\n\nContact Support:\n Name: nodoc", "type": "text/plain" } } }