Create an MDM control
Create a new MDM control of the given type with its configurationPayload and targeting. Discover creatable types and their config JSON Schema via GET /mdm-controls/catalog. name is optional — when omitted, the catalog default name for the type is used; supply a name to create several controls of one type (some profile-backed types require unique names). enabled defaults to true, so a created control is deployed to its targeted devices immediately. configurationPayload must match the type’s config schema (send null for config-less types). Targeting is set via targetMethod: “All” (every device) or “DeviceGroup” (includedDeviceGroupIds/excludedDeviceGroupIds). Returns the created control id. Invalid config/targeting returns 400, an unknown device group 404, a name/profile conflict 409, MDM not configured for the company 412, and demo companies are not allowed to create MDM controls (403).
Authorizations
Use your Primo API key in the Authorization header as Bearer <API_KEY>.
Body
Control type discriminator, e.g. "wifi_macos". Discover the creatable types and each type's config JSON Schema via GET /mdm-controls/catalog.
malwarebyte_macos, malwarebyte_windows, malwarebyte_linux, recoveryOs_macos, softwareUpdate_macos, appBlocking_macos, wifi_macos, wifi_ios, wifi_ipados, wifi_windows, wifi_android, wifi_linux, adminUserManagement_macos, adminUserManagement_windows, adminUserPasswordRotation_macos, adminUserPasswordRotation_windows, deviceNaming_macos, deviceNaming_windows, deviceNaming_linux, googleChrome_macos, googleChrome_windows, firewall_macos, firewall_windows, usbBlocking_macos, usbBlocking_windows, usbBlocking_linux, entraSSO_macos, oktaSSO_macos, primoSSO_macos, customFile_macos, customFile_ios, customFile_ipados, customFile_windows, customFile_android, customFile_linux, passwordPolicy_macos, passwordPolicy_windows, passwordPolicy_ios, passwordPolicy_ipados, passwordPolicy_android, sentinelOne_macos, sentinelOne_windows, sentinelOne_windows_arm64, sentinelOne_linux_deb, sentinelOne_linux_deb_arm64, sentinelOne_linux_rpm, sentinelOne_linux_rpm_arm64, diskEncryption_all, osUpdate_macos, osUpdate_windows, osUpdate_ios, osUpdate_ipados, rustdesk_macos, rustdesk_windows, disableProfilesPane_macos, screenCapture_macos, disableAirdrop_macos, airPrint_macos, webClip_macos, webClip_ios, webClip_ipados Configuration payload for the control, in clear values, matching the type's config JSON Schema (see GET /mdm-controls/catalog). Send null for control types that take no config.
How the control is targeted. "All" targets every device (ignores the group fields below); "DeviceGroup" uses the included/excluded group lists.
All, DeviceGroup Display name for the control. Omit to use the catalog default name for the given type. Supply a name to create several controls of the same type — some profile-backed types require a unique name.
Whether the control is active once created. Defaults to true when omitted.
Device group IDs to include. Used only when targetMethod is "DeviceGroup".
Device group IDs to exclude. Used only when targetMethod is "DeviceGroup".
Response
ID of the created MDM control.