Hello Sophos Central API Support,
we have been using the Sophos API for some months now and we never had problems receiving a token, tenants and endpoint data using always one key.
We have asked Sophos Support about this problem but the answer did not help us further and we should now ask this in the Sophos Central API forum.
Now this month september 2021, we have started to collect the september data and nothing in our software has been changed.
But now we get the Error ‘Forbidden’ by trying to get the Endpoints of a tenant.
Current temporarily Solution : We created a new key (with the same rights) and used it in our software and it works again, but we have a lot of configurations with the old key who has stopped working and perhaps we can fix this so we do not have to reconfigure, which will be lot of work to do.
There are 2 suggestions from Sophos Support what we can to do find out the reason for the problem:
- Verify with postman: We tried to verify the error with postman and got the same error.
- We should use Logz.io to analyse the traffic. We created a Trial Account which we should use to analyse the traffic details.
We are not able to find the Option to “request the full query”. We never used this tool before, so we need detailed instructions, how to use it, to get the desired information.
Our Question: Why did the old account stop working, while the new account, with the same rights, is working?
Kind regards
Ralph Felger