Safeguard API Coverage Documentation

The 133 Meraki dashboard settings Safeguard backs up, by dashboard area, with the API operation behind each one, and what is not covered.
Written by Boundless
Updated 2 weeks ago

Revision: 28 August 2026. Previous revision: 23 December 2025. Validated against the Cisco Meraki generally available API index (983 endpoints).

Safeguard backs up configuration, not data. This article lists every configuration setting it reads out of Cisco Networking Cloud, the Meraki API operation behind each one, and the settings it does not cover. The operation names are included so your security or network team can verify each claim against Cisco's own API reference rather than taking ours on trust.

Configuration settings backed up 133
Meraki API operations called 143
Dashboard areas covered 11

How coverage is decided

Generally available endpoints only. Safeguard uses Meraki API endpoints with a stable, published contract. Beta endpoints are excluded, because a backup that depends on an endpoint that can change without notice is not a backup. If a covered endpoint starts returning errors, we pause it and tell you before the next scheduled run.

Configuration, not telemetry. Cisco publishes 162 monitoring endpoints and 29 live-tool endpoints alongside the configuration ones. They return client lists, usage, event logs and diagnostics. None of that is configuration, so none of it is in a configuration backup.

Restore uses the matching write operation. Where Cisco exposes a write for a setting, Safeguard can put it back. A small number of organization-level views are restored network by network, because that is the scope at which Cisco exposes the write.

Secrets are the one gap inside covered settings. Meraki returns RADIUS shared secrets, pre-shared keys and IPsec keys as write-only, for good reason. Safeguard captures and restores the setting around them; the secret itself has to be re-supplied at restore time.

Coverage by dashboard area

Organization (20 settings)

Organization-wide constructs that every network inherits: administrators, identity, policy objects and templates.

Configuration backed up Meraki API operation
Adaptive Policy ACLs getOrganizationAdaptivePolicyAcls
Adaptive Policy global settings getOrganizationAdaptivePolicySettings
Adaptive Policy groups (SGTs) getOrganizationAdaptivePolicyGroups
Adaptive Policy matrix (group-to-group bindings) getOrganizationAdaptivePolicyPolicies
Branding policies (what each admin role can see and do) getOrganizationBrandingPolicies
Branding policy priority order getOrganizationBrandingPoliciesPriorities
Configuration templates getOrganizationConfigTemplates
Dashboard administrators and their access levels getOrganizationAdmins
Device inventory (serial, model, network binding, tags) getOrganizationInventoryDevices
Early access feature opt-ins getOrganizationEarlyAccessFeaturesOptIns
Login security policy (MFA, password rules, idle timeout, IP allowlist) getOrganizationLoginSecurity
Network inventory (name, type, tags, time zone) getOrganizationNetworks
Organization settings (name, cloud region, API access) getOrganization
Organization SNMP settings getOrganizationSnmp
Organization-wide alert profiles getOrganizationAlertsProfiles
Policy object groups getOrganizationPolicyObjectsGroups
Policy objects (IPs, FQDNs, CIDRs) getOrganizationPolicyObjects
SAML identity providers (X.509 fingerprints, SLO URLs) getOrganizationSamlIdps
SAML roles and network/tag privileges getOrganizationSamlRoles
SAML SSO enable/disable getOrganizationSaml

Network-wide (14 settings)

The settings that define a site: identity, group policies, alerting, telemetry configuration and firmware behaviour.

Configuration backed up Meraki API operation
Firmware upgrade settings and maintenance windows getNetworkFirmwareUpgrades
Floor plans and their geo-anchoring getNetworkFloorPlans
Group policies (bandwidth, firewall, traffic shaping, VLAN, splash) getNetworkGroupPolicies
Meraki-authenticated users (802.1X, splash guest, client VPN) getNetworkMerakiAuthUsers
MQTT brokers getNetworkMqttBrokers
NetFlow and traffic reporting settings getNetworkNetflow
Network alert settings and recipients getNetworkAlertsSettings
Network identity (name, tags, product types, time zone) getNetwork
Network settings (local status page, remote access, client tracking) getNetworkSettings
Network SNMP settings getNetworkSnmp
Staged upgrade groups and events getNetworkFirmwareUpgradesStagedEvents, getNetworkFirmwareUpgradesStagedGroups, getNetworkFirmwareUpgradesStagedStages
Traffic analysis settings and custom pie chart items getNetworkTrafficAnalysis
Webhook HTTP servers getNetworkWebhooksHttpServers
Webhook payload templates getNetworkWebhooksPayloadTemplates

Security & SD-WAN (35 settings)

The MX estate: addressing, firewall and NAT, content filtering, VPN and SD-WAN policy.

Configuration backed up Meraki API operation
1:1 NAT rules getNetworkApplianceFirewallOneToOneNatRules
1:Many NAT rules getNetworkApplianceFirewallOneToManyNatRules
Anti-malware (AMP) settings and allowlists getNetworkApplianceSecurityMalware
Appliance service access (ICMP, web, SNMP) getNetworkApplianceFirewallFirewalledServices
Appliance settings (deployment mode, dynamic DNS) getNetworkApplianceSettings
BGP configuration on VPN hubs getNetworkApplianceVpnBgp
Cellular firewall rules getNetworkApplianceFirewallCellularFirewallRules
Connectivity monitoring destinations getNetworkApplianceConnectivityMonitoringDestinations
Content filtering (blocked categories, allow/block URLs) getNetworkApplianceContentFiltering
Custom performance classes getNetworkApplianceTrafficShapingCustomPerformanceClasses
IDS/IPS settings (network and organization ruleset) getNetworkApplianceSecurityIntrusion, getOrganizationApplianceSecurityIntrusion
Inbound cellular firewall rules getNetworkApplianceFirewallInboundCellularFirewallRules
Inbound firewall rules getNetworkApplianceFirewallInboundFirewallRules
Layer 3 outbound firewall rules getNetworkApplianceFirewallL3FirewallRules
Layer 7 firewall rules getNetworkApplianceFirewallL7FirewallRules
MX per-port VLAN configuration getNetworkAppliancePorts
MX radio settings getDeviceApplianceRadioSettings
MX RF profiles getNetworkApplianceRfProfiles
MX wireless SSIDs getNetworkApplianceSsids
Non-Meraki VPN peers (IKE settings, PSK reference) getOrganizationApplianceVpnThirdPartyVPNPeers
Per-appliance uplink settings (WAN IP, VLAN tagging, PPPoE) getDeviceApplianceUplinksSettings
Port forwarding rules getNetworkApplianceFirewallPortForwardingRules
SD-WAN uplink selection and policies getNetworkApplianceTrafficShapingUplinkSelection
Single-LAN configuration getNetworkApplianceSingleLan
Site-to-site VPN (hub/spoke topology, exported subnets) getNetworkApplianceVpnSiteToSiteVpn
Site-to-site VPN firewall rules getOrganizationApplianceVpnVpnFirewallRules
Spoofing protection settings getNetworkApplianceFirewallSettings
Static delegated IPv6 prefixes getNetworkAppliancePrefixesDelegatedStatics
Static routes getNetworkApplianceStaticRoutes
Traffic shaping global settings getNetworkApplianceTrafficShaping
Traffic shaping rules and DSCP tagging getNetworkApplianceTrafficShapingRules
Uplink bandwidth limits getNetworkApplianceTrafficShapingUplinkBandwidth
VLAN mode enabled/disabled getNetworkApplianceVlansSettings
VLANs (subnet, appliance IP, DHCP, reservations, options) getNetworkApplianceVlans
Warm spare (HA) settings getNetworkApplianceWarmSpare

Switching (24 settings)

Port-level configuration, access policies, Layer 3 routing and stack topology.

Configuration backed up Meraki API operation
Access policies (802.1X, RADIUS servers, guest VLAN) getNetworkSwitchAccessPolicies
Alternate management interface getNetworkSwitchAlternateManagementInterface
DHCP server policy (allow/block lists) getNetworkSwitchDhcpServerPolicy
DSCP to CoS mappings getNetworkSwitchDscpToCosMappings
Dynamic ARP Inspection trusted servers getNetworkSwitchDhcpServerPolicyArpInspectionTrustedServers
Layer 3 interfaces and their DHCP configuration getDeviceSwitchRoutingInterfaceDhcp, getDeviceSwitchRoutingInterfaces
Layer 3 static routes getDeviceSwitchRoutingStaticRoutes
Link aggregation groups getNetworkSwitchLinkAggregations
MTU configuration getNetworkSwitchMtu
Multicast settings and rendezvous points getNetworkSwitchRoutingMulticast, getNetworkSwitchRoutingMulticastRendezvousPoints
OSPF configuration getNetworkSwitchRoutingOspf
Port schedules getNetworkSwitchPortSchedules
QoS rule order getNetworkSwitchQosRulesOrder
QoS rules getNetworkSwitchQosRules
Spanning tree settings and bridge priorities getNetworkSwitchStp
Stack Layer 3 interfaces, DHCP and static routes getNetworkSwitchStackRoutingInterfaceDhcp, getNetworkSwitchStackRoutingInterfaces, getNetworkSwitchStackRoutingStaticRoutes
Storm control thresholds getNetworkSwitchStormControl
Switch ACLs getNetworkSwitchAccessControlLists
Switch network settings (VLAN, MAC blocklist, uplink client sampling) getNetworkSwitchSettings
Switch port configuration (VLAN, PoE, type, tags, STP) getDeviceSwitchPorts
Switch profile port settings getOrganizationConfigTemplateSwitchProfilePorts
Switch profiles (templates) and their port configuration getOrganizationConfigTemplateSwitchProfiles
Switch stacks and membership getNetworkSwitchStacks
Switch warm spare configuration getDeviceSwitchWarmSpare

Wireless (18 settings)

SSIDs and every setting hanging off them, plus RF profiles and per-AP overrides.

Configuration backed up Meraki API operation
Alternate management interface and assigned IPs getNetworkWirelessAlternateManagementInterface
AP port profiles getNetworkWirelessEthernetPortsProfiles
Billing / paid-access settings getNetworkWirelessBilling
Bluetooth / BLE settings, network and per-AP getDeviceWirelessBluetoothSettings, getNetworkWirelessBluetoothSettings
Bonjour forwarding rules getNetworkWirelessSsidBonjourForwarding
Device-type group policies per SSID getNetworkWirelessSsidDeviceTypeGroupPolicies
EAP parameter overrides getNetworkWirelessSsidEapOverride
Hotspot 2.0 settings getNetworkWirelessSsidHotspot20
Identity PSKs getNetworkWirelessSsidIdentityPsks
Per-AP radio overrides (channel, power) getDeviceWirelessRadioSettings
RF profiles (band, power, channel width, min bitrate) getNetworkWirelessRfProfiles
Splash page settings per SSID getNetworkWirelessSsidSplashSettings
SSID availability schedules getNetworkWirelessSsidSchedules
SSID Layer 3 and Layer 7 firewall rules getNetworkWirelessSsidFirewallL3FirewallRules, getNetworkWirelessSsidFirewallL7FirewallRules
SSID traffic shaping rules getNetworkWirelessSsidTrafficShapingRules
SSID VPN (concentrator, split tunnel, failover) getNetworkWirelessSsidVpn
SSIDs (auth mode, encryption, VLAN tagging, band selection) getNetworkWirelessSsids
Wireless network settings (meshing, IPv6 bridge, LED, upgrade strategy) getNetworkWirelessSettings

Cameras (7 settings)

Retention, analytics and access control. Video itself is never copied.

Configuration backed up Meraki API operation
Camera roles getOrganizationCameraRoles
Camera wireless profiles and assignments getDeviceCameraWirelessProfiles, getNetworkCameraWirelessProfiles
Custom analytics settings getDeviceCameraCustomAnalytics
MV Sense settings and MQTT getDeviceCameraSense
Per-camera quality and retention settings getDeviceCameraQualityAndRetention
Quality and retention profiles getNetworkCameraQualityRetentionProfiles
Video settings (external RTSP) getDeviceCameraVideoSettings

Systems Manager (2 settings)

Target groups and administrator roles.

Configuration backed up Meraki API operation
SM administrator roles getOrganizationSmAdminsRoles
SM target groups getNetworkSmTargetGroups

Cellular Gateway (6 settings)

MG addressing, DHCP and uplink policy.

Configuration backed up Meraki API operation
MG connectivity monitoring destinations getNetworkCellularGatewayConnectivityMonitoringDestinations
MG DHCP settings getNetworkCellularGatewayDhcp
MG LAN settings and fixed IP assignments getDeviceCellularGatewayLan
MG port forwarding rules getDeviceCellularGatewayPortForwardingRules
MG subnet pool and mask getNetworkCellularGatewaySubnetPool
MG uplink bandwidth settings getNetworkCellularGatewayUplink

Sensors (3 settings)

Alert profiles, thresholds and broker settings.

Configuration backed up Meraki API operation
Sensor alert profiles and thresholds getNetworkSensorAlertsProfiles
Sensor MQTT broker settings getNetworkSensorMqttBrokers
Sensor to camera relationships getDeviceSensorRelationships

Devices (3 settings)

Device-level settings that survive independently of the network they sit in.

Configuration backed up Meraki API operation
Device attributes (name, tags, address, notes, floor plan) getDevice
Device management interface (static IP, VLAN, DNS) getDeviceManagementInterface
SIM and APN configuration getDeviceCellularSims

Insight (1 settings)

Monitored media server definitions.

Configuration backed up Meraki API operation
Monitored media servers getOrganizationInsightMonitoredMediaServers

What is not backed up

Not configuration

Category Why
Live and historical telemetry 162 monitoring endpoints: client lists, usage, event logs, latency, uplink history, air marshal scans, wireless health.
Live tools and diagnostics 29 action endpoints: ping, cable test, throughput test, ARP and routing table lookups, LED blink, reboot.
Camera video and packet captures Recorded video, snapshots and pcap files are data, not configuration.
Personally identifiable information PII keys, PII requests and Systems Manager owner lookups are deliberately excluded.
Secrets Meraki never returns RADIUS shared secrets, PSKs, IPsec pre-shared keys and API keys are write-only in the API. Restore re-applies the object; the secret has to be supplied.
Anything outside the GA API Configuration Meraki exposes only in the dashboard UI, or in beta endpoints, cannot be captured by any API-based backup tool.

Not yet reachable with a scoped OAuth grant

Safeguard connects to your organization through a scoped OAuth integration rather than a static API key, so it can never do more than it is granted. Cisco is expanding the OAuth scope release by release. At this revision, 141 configuration endpoints sit outside it and are therefore outside Safeguard's coverage. They move into the tables above as Cisco opens them.

Area Endpoints
Secure Connect / SASE 12
Cisco Umbrella integration 6
Organization-wide SSID profiles 6
SSID isolation allowlist 4
Splash themes and assets 6
Cellular data profiles 7
Per-AP radio overrides, RRM and auto-RF 6
Air Marshal (org-level settings and rule writes) 5
Electronic shelf label and Zigbee 15
Action batches 5
SM admin roles, Sentry policies and device actions 13
Campus gateway failover and uplink overrides 9
eSIM inventory, providers and swaps 7
Insight monitored media servers 5
Appliance L3 interfaces, NAT and IPsec SLAs 11
Provisioning pipelines and integrations 4
AP provisioning deployments 4
Catalyst controller migrations 2
Org create, clone and order-level inventory 3
Cellular uplink and geolocation settings 2
Own API keys and identity 3
Other organization-level reads 6

Changelog

28 August 2026. Full revalidation against the Meraki GA API index. Removed five operation names that Cisco has since renamed or retired. Reorganised the list by dashboard area with plain-language setting names alongside the operation IDs. Added the sections above covering what is not backed up and why.

23 December 2025. Initial published coverage list.

Did this answer your question?