Skip to main content
POST
Create an MDM control
Key: Write Scope: Company

Authorizations

Authorization
string
header
required

Use your Primo API key in the Authorization header as Bearer <API_KEY>.

Body

application/json
type
enum<string>
required

Control type discriminator, e.g. "wifi_macos". Discover the creatable types and each type's config JSON Schema via GET /mdm-controls/catalog.

Available options:
malwarebyte_macos,
malwarebyte_windows,
malwarebyte_linux,
recoveryOs_macos,
softwareUpdate_macos,
appBlocking_macos,
wifi_macos,
wifi_ios,
wifi_ipados,
wifi_windows,
wifi_android,
wifi_linux,
adminUserManagement_macos,
adminUserManagement_windows,
adminUserPasswordRotation_macos,
adminUserPasswordRotation_windows,
deviceNaming_macos,
deviceNaming_windows,
deviceNaming_linux,
googleChrome_macos,
googleChrome_windows,
firewall_macos,
firewall_windows,
usbBlocking_macos,
usbBlocking_windows,
usbBlocking_linux,
entraSSO_macos,
oktaSSO_macos,
primoSSO_macos,
customFile_macos,
customFile_ios,
customFile_ipados,
customFile_windows,
customFile_android,
customFile_linux,
passwordPolicy_macos,
passwordPolicy_windows,
passwordPolicy_ios,
passwordPolicy_ipados,
passwordPolicy_android,
sentinelOne_macos,
sentinelOne_windows,
sentinelOne_windows_arm64,
sentinelOne_linux_deb,
sentinelOne_linux_deb_arm64,
sentinelOne_linux_rpm,
sentinelOne_linux_rpm_arm64,
diskEncryption_all,
osUpdate_macos,
osUpdate_windows,
osUpdate_ios,
osUpdate_ipados,
rustdesk_macos,
rustdesk_windows,
disableProfilesPane_macos,
screenCapture_macos,
disableAirdrop_macos,
airPrint_macos,
webClip_macos,
webClip_ios,
webClip_ipados
configurationPayload
object | null
required

Configuration payload for the control, in clear values, matching the type's config JSON Schema (see GET /mdm-controls/catalog). Send null for control types that take no config.

targetMethod
enum<string>
required

How the control is targeted. "All" targets every device (ignores the group fields below); "DeviceGroup" uses the included/excluded group lists.

Available options:
All,
DeviceGroup
name
string

Display name for the control. Omit to use the catalog default name for the given type. Supply a name to create several controls of the same type — some profile-backed types require a unique name.

enabled
boolean

Whether the control is active once created. Defaults to true when omitted.

includedDeviceGroupIds
string[]

Device group IDs to include. Used only when targetMethod is "DeviceGroup".

excludedDeviceGroupIds
string[]

Device group IDs to exclude. Used only when targetMethod is "DeviceGroup".

Response

default - application/json
id
string
required

ID of the created MDM control.