Skip to main content
GET

Overview

The Users endpoint aggregates user account information from all connected directory services and identity providers (Active Directory, Azure AD, Google Workspace, etc.).

Parameters
string
default:"all"
Filter users based on their current state
number
default:"0"
Set the start position of the data returned by the API
number
default:"0"
Limit each request by the provided number. Leave blank or as 0 to return all data available

Authentication

string
required
Your ThreatAware API key
string
default:"application/json"
Response format

Response

number
The starting position of this result set
number
The number of results returned
number
Total number of users available
boolean
Whether the request was successful
number
HTTP status code
string
Status message
array

Use Cases

User Access Auditing

Track which users have accessed which systems and from where

MFA Coverage Reporting

Identify users without MFA enabled across identity providers

Offboarding Validation

Verify user account deactivation across all connected systems

Geographic Access Analysis

Monitor login patterns and detect unusual geographic access