Revision: 28 August 2026. Previous revision: 23 December 2025. Validated against the Cisco Meraki generally available API index (983 endpoints).
Safeguard backs up configuration, not data. This article lists every configuration setting it reads out of Cisco Networking Cloud, the Meraki API operation behind each one, and the settings it does not cover. The operation names are included so your security or network team can verify each claim against Cisco's own API reference rather than taking ours on trust.
| Configuration settings backed up | 133 |
| Meraki API operations called | 143 |
| Dashboard areas covered | 11 |
How coverage is decided
Generally available endpoints only. Safeguard uses Meraki API endpoints with a stable, published contract. Beta endpoints are excluded, because a backup that depends on an endpoint that can change without notice is not a backup. If a covered endpoint starts returning errors, we pause it and tell you before the next scheduled run.
Configuration, not telemetry. Cisco publishes 162 monitoring endpoints and 29 live-tool endpoints alongside the configuration ones. They return client lists, usage, event logs and diagnostics. None of that is configuration, so none of it is in a configuration backup.
Restore uses the matching write operation. Where Cisco exposes a write for a setting, Safeguard can put it back. A small number of organization-level views are restored network by network, because that is the scope at which Cisco exposes the write.
Secrets are the one gap inside covered settings. Meraki returns RADIUS shared secrets, pre-shared keys and IPsec keys as write-only, for good reason. Safeguard captures and restores the setting around them; the secret itself has to be re-supplied at restore time.
Coverage by dashboard area
Organization (20 settings)
Organization-wide constructs that every network inherits: administrators, identity, policy objects and templates.
| Configuration backed up | Meraki API operation |
|---|---|
| Adaptive Policy ACLs | getOrganizationAdaptivePolicyAcls |
| Adaptive Policy global settings | getOrganizationAdaptivePolicySettings |
| Adaptive Policy groups (SGTs) | getOrganizationAdaptivePolicyGroups |
| Adaptive Policy matrix (group-to-group bindings) | getOrganizationAdaptivePolicyPolicies |
| Branding policies (what each admin role can see and do) | getOrganizationBrandingPolicies |
| Branding policy priority order | getOrganizationBrandingPoliciesPriorities |
| Configuration templates | getOrganizationConfigTemplates |
| Dashboard administrators and their access levels | getOrganizationAdmins |
| Device inventory (serial, model, network binding, tags) | getOrganizationInventoryDevices |
| Early access feature opt-ins | getOrganizationEarlyAccessFeaturesOptIns |
| Login security policy (MFA, password rules, idle timeout, IP allowlist) | getOrganizationLoginSecurity |
| Network inventory (name, type, tags, time zone) | getOrganizationNetworks |
| Organization settings (name, cloud region, API access) | getOrganization |
| Organization SNMP settings | getOrganizationSnmp |
| Organization-wide alert profiles | getOrganizationAlertsProfiles |
| Policy object groups | getOrganizationPolicyObjectsGroups |
| Policy objects (IPs, FQDNs, CIDRs) | getOrganizationPolicyObjects |
| SAML identity providers (X.509 fingerprints, SLO URLs) | getOrganizationSamlIdps |
| SAML roles and network/tag privileges | getOrganizationSamlRoles |
| SAML SSO enable/disable | getOrganizationSaml |
Network-wide (14 settings)
The settings that define a site: identity, group policies, alerting, telemetry configuration and firmware behaviour.
| Configuration backed up | Meraki API operation |
|---|---|
| Firmware upgrade settings and maintenance windows | getNetworkFirmwareUpgrades |
| Floor plans and their geo-anchoring | getNetworkFloorPlans |
| Group policies (bandwidth, firewall, traffic shaping, VLAN, splash) | getNetworkGroupPolicies |
| Meraki-authenticated users (802.1X, splash guest, client VPN) | getNetworkMerakiAuthUsers |
| MQTT brokers | getNetworkMqttBrokers |
| NetFlow and traffic reporting settings | getNetworkNetflow |
| Network alert settings and recipients | getNetworkAlertsSettings |
| Network identity (name, tags, product types, time zone) | getNetwork |
| Network settings (local status page, remote access, client tracking) | getNetworkSettings |
| Network SNMP settings | getNetworkSnmp |
| Staged upgrade groups and events | getNetworkFirmwareUpgradesStagedEvents, getNetworkFirmwareUpgradesStagedGroups, getNetworkFirmwareUpgradesStagedStages |
| Traffic analysis settings and custom pie chart items | getNetworkTrafficAnalysis |
| Webhook HTTP servers | getNetworkWebhooksHttpServers |
| Webhook payload templates | getNetworkWebhooksPayloadTemplates |
Security & SD-WAN (35 settings)
The MX estate: addressing, firewall and NAT, content filtering, VPN and SD-WAN policy.
| Configuration backed up | Meraki API operation |
|---|---|
| 1:1 NAT rules | getNetworkApplianceFirewallOneToOneNatRules |
| 1:Many NAT rules | getNetworkApplianceFirewallOneToManyNatRules |
| Anti-malware (AMP) settings and allowlists | getNetworkApplianceSecurityMalware |
| Appliance service access (ICMP, web, SNMP) | getNetworkApplianceFirewallFirewalledServices |
| Appliance settings (deployment mode, dynamic DNS) | getNetworkApplianceSettings |
| BGP configuration on VPN hubs | getNetworkApplianceVpnBgp |
| Cellular firewall rules | getNetworkApplianceFirewallCellularFirewallRules |
| Connectivity monitoring destinations | getNetworkApplianceConnectivityMonitoringDestinations |
| Content filtering (blocked categories, allow/block URLs) | getNetworkApplianceContentFiltering |
| Custom performance classes | getNetworkApplianceTrafficShapingCustomPerformanceClasses |
| IDS/IPS settings (network and organization ruleset) | getNetworkApplianceSecurityIntrusion, getOrganizationApplianceSecurityIntrusion |
| Inbound cellular firewall rules | getNetworkApplianceFirewallInboundCellularFirewallRules |
| Inbound firewall rules | getNetworkApplianceFirewallInboundFirewallRules |
| Layer 3 outbound firewall rules | getNetworkApplianceFirewallL3FirewallRules |
| Layer 7 firewall rules | getNetworkApplianceFirewallL7FirewallRules |
| MX per-port VLAN configuration | getNetworkAppliancePorts |
| MX radio settings | getDeviceApplianceRadioSettings |
| MX RF profiles | getNetworkApplianceRfProfiles |
| MX wireless SSIDs | getNetworkApplianceSsids |
| Non-Meraki VPN peers (IKE settings, PSK reference) | getOrganizationApplianceVpnThirdPartyVPNPeers |
| Per-appliance uplink settings (WAN IP, VLAN tagging, PPPoE) | getDeviceApplianceUplinksSettings |
| Port forwarding rules | getNetworkApplianceFirewallPortForwardingRules |
| SD-WAN uplink selection and policies | getNetworkApplianceTrafficShapingUplinkSelection |
| Single-LAN configuration | getNetworkApplianceSingleLan |
| Site-to-site VPN (hub/spoke topology, exported subnets) | getNetworkApplianceVpnSiteToSiteVpn |
| Site-to-site VPN firewall rules | getOrganizationApplianceVpnVpnFirewallRules |
| Spoofing protection settings | getNetworkApplianceFirewallSettings |
| Static delegated IPv6 prefixes | getNetworkAppliancePrefixesDelegatedStatics |
| Static routes | getNetworkApplianceStaticRoutes |
| Traffic shaping global settings | getNetworkApplianceTrafficShaping |
| Traffic shaping rules and DSCP tagging | getNetworkApplianceTrafficShapingRules |
| Uplink bandwidth limits | getNetworkApplianceTrafficShapingUplinkBandwidth |
| VLAN mode enabled/disabled | getNetworkApplianceVlansSettings |
| VLANs (subnet, appliance IP, DHCP, reservations, options) | getNetworkApplianceVlans |
| Warm spare (HA) settings | getNetworkApplianceWarmSpare |
Switching (24 settings)
Port-level configuration, access policies, Layer 3 routing and stack topology.
| Configuration backed up | Meraki API operation |
|---|---|
| Access policies (802.1X, RADIUS servers, guest VLAN) | getNetworkSwitchAccessPolicies |
| Alternate management interface | getNetworkSwitchAlternateManagementInterface |
| DHCP server policy (allow/block lists) | getNetworkSwitchDhcpServerPolicy |
| DSCP to CoS mappings | getNetworkSwitchDscpToCosMappings |
| Dynamic ARP Inspection trusted servers | getNetworkSwitchDhcpServerPolicyArpInspectionTrustedServers |
| Layer 3 interfaces and their DHCP configuration | getDeviceSwitchRoutingInterfaceDhcp, getDeviceSwitchRoutingInterfaces |
| Layer 3 static routes | getDeviceSwitchRoutingStaticRoutes |
| Link aggregation groups | getNetworkSwitchLinkAggregations |
| MTU configuration | getNetworkSwitchMtu |
| Multicast settings and rendezvous points | getNetworkSwitchRoutingMulticast, getNetworkSwitchRoutingMulticastRendezvousPoints |
| OSPF configuration | getNetworkSwitchRoutingOspf |
| Port schedules | getNetworkSwitchPortSchedules |
| QoS rule order | getNetworkSwitchQosRulesOrder |
| QoS rules | getNetworkSwitchQosRules |
| Spanning tree settings and bridge priorities | getNetworkSwitchStp |
| Stack Layer 3 interfaces, DHCP and static routes | getNetworkSwitchStackRoutingInterfaceDhcp, getNetworkSwitchStackRoutingInterfaces, getNetworkSwitchStackRoutingStaticRoutes |
| Storm control thresholds | getNetworkSwitchStormControl |
| Switch ACLs | getNetworkSwitchAccessControlLists |
| Switch network settings (VLAN, MAC blocklist, uplink client sampling) | getNetworkSwitchSettings |
| Switch port configuration (VLAN, PoE, type, tags, STP) | getDeviceSwitchPorts |
| Switch profile port settings | getOrganizationConfigTemplateSwitchProfilePorts |
| Switch profiles (templates) and their port configuration | getOrganizationConfigTemplateSwitchProfiles |
| Switch stacks and membership | getNetworkSwitchStacks |
| Switch warm spare configuration | getDeviceSwitchWarmSpare |
Wireless (18 settings)
SSIDs and every setting hanging off them, plus RF profiles and per-AP overrides.
| Configuration backed up | Meraki API operation |
|---|---|
| Alternate management interface and assigned IPs | getNetworkWirelessAlternateManagementInterface |
| AP port profiles | getNetworkWirelessEthernetPortsProfiles |
| Billing / paid-access settings | getNetworkWirelessBilling |
| Bluetooth / BLE settings, network and per-AP | getDeviceWirelessBluetoothSettings, getNetworkWirelessBluetoothSettings |
| Bonjour forwarding rules | getNetworkWirelessSsidBonjourForwarding |
| Device-type group policies per SSID | getNetworkWirelessSsidDeviceTypeGroupPolicies |
| EAP parameter overrides | getNetworkWirelessSsidEapOverride |
| Hotspot 2.0 settings | getNetworkWirelessSsidHotspot20 |
| Identity PSKs | getNetworkWirelessSsidIdentityPsks |
| Per-AP radio overrides (channel, power) | getDeviceWirelessRadioSettings |
| RF profiles (band, power, channel width, min bitrate) | getNetworkWirelessRfProfiles |
| Splash page settings per SSID | getNetworkWirelessSsidSplashSettings |
| SSID availability schedules | getNetworkWirelessSsidSchedules |
| SSID Layer 3 and Layer 7 firewall rules | getNetworkWirelessSsidFirewallL3FirewallRules, getNetworkWirelessSsidFirewallL7FirewallRules |
| SSID traffic shaping rules | getNetworkWirelessSsidTrafficShapingRules |
| SSID VPN (concentrator, split tunnel, failover) | getNetworkWirelessSsidVpn |
| SSIDs (auth mode, encryption, VLAN tagging, band selection) | getNetworkWirelessSsids |
| Wireless network settings (meshing, IPv6 bridge, LED, upgrade strategy) | getNetworkWirelessSettings |
Cameras (7 settings)
Retention, analytics and access control. Video itself is never copied.
| Configuration backed up | Meraki API operation |
|---|---|
| Camera roles | getOrganizationCameraRoles |
| Camera wireless profiles and assignments | getDeviceCameraWirelessProfiles, getNetworkCameraWirelessProfiles |
| Custom analytics settings | getDeviceCameraCustomAnalytics |
| MV Sense settings and MQTT | getDeviceCameraSense |
| Per-camera quality and retention settings | getDeviceCameraQualityAndRetention |
| Quality and retention profiles | getNetworkCameraQualityRetentionProfiles |
| Video settings (external RTSP) | getDeviceCameraVideoSettings |
Systems Manager (2 settings)
Target groups and administrator roles.
| Configuration backed up | Meraki API operation |
|---|---|
| SM administrator roles | getOrganizationSmAdminsRoles |
| SM target groups | getNetworkSmTargetGroups |
Cellular Gateway (6 settings)
MG addressing, DHCP and uplink policy.
| Configuration backed up | Meraki API operation |
|---|---|
| MG connectivity monitoring destinations | getNetworkCellularGatewayConnectivityMonitoringDestinations |
| MG DHCP settings | getNetworkCellularGatewayDhcp |
| MG LAN settings and fixed IP assignments | getDeviceCellularGatewayLan |
| MG port forwarding rules | getDeviceCellularGatewayPortForwardingRules |
| MG subnet pool and mask | getNetworkCellularGatewaySubnetPool |
| MG uplink bandwidth settings | getNetworkCellularGatewayUplink |
Sensors (3 settings)
Alert profiles, thresholds and broker settings.
| Configuration backed up | Meraki API operation |
|---|---|
| Sensor alert profiles and thresholds | getNetworkSensorAlertsProfiles |
| Sensor MQTT broker settings | getNetworkSensorMqttBrokers |
| Sensor to camera relationships | getDeviceSensorRelationships |
Devices (3 settings)
Device-level settings that survive independently of the network they sit in.
| Configuration backed up | Meraki API operation |
|---|---|
| Device attributes (name, tags, address, notes, floor plan) | getDevice |
| Device management interface (static IP, VLAN, DNS) | getDeviceManagementInterface |
| SIM and APN configuration | getDeviceCellularSims |
Insight (1 settings)
Monitored media server definitions.
| Configuration backed up | Meraki API operation |
|---|---|
| Monitored media servers | getOrganizationInsightMonitoredMediaServers |
What is not backed up
Not configuration
| Category | Why |
|---|---|
| Live and historical telemetry | 162 monitoring endpoints: client lists, usage, event logs, latency, uplink history, air marshal scans, wireless health. |
| Live tools and diagnostics | 29 action endpoints: ping, cable test, throughput test, ARP and routing table lookups, LED blink, reboot. |
| Camera video and packet captures | Recorded video, snapshots and pcap files are data, not configuration. |
| Personally identifiable information | PII keys, PII requests and Systems Manager owner lookups are deliberately excluded. |
| Secrets Meraki never returns | RADIUS shared secrets, PSKs, IPsec pre-shared keys and API keys are write-only in the API. Restore re-applies the object; the secret has to be supplied. |
| Anything outside the GA API | Configuration Meraki exposes only in the dashboard UI, or in beta endpoints, cannot be captured by any API-based backup tool. |
Not yet reachable with a scoped OAuth grant
Safeguard connects to your organization through a scoped OAuth integration rather than a static API key, so it can never do more than it is granted. Cisco is expanding the OAuth scope release by release. At this revision, 141 configuration endpoints sit outside it and are therefore outside Safeguard's coverage. They move into the tables above as Cisco opens them.
| Area | Endpoints |
|---|---|
| Secure Connect / SASE | 12 |
| Cisco Umbrella integration | 6 |
| Organization-wide SSID profiles | 6 |
| SSID isolation allowlist | 4 |
| Splash themes and assets | 6 |
| Cellular data profiles | 7 |
| Per-AP radio overrides, RRM and auto-RF | 6 |
| Air Marshal (org-level settings and rule writes) | 5 |
| Electronic shelf label and Zigbee | 15 |
| Action batches | 5 |
| SM admin roles, Sentry policies and device actions | 13 |
| Campus gateway failover and uplink overrides | 9 |
| eSIM inventory, providers and swaps | 7 |
| Insight monitored media servers | 5 |
| Appliance L3 interfaces, NAT and IPsec SLAs | 11 |
| Provisioning pipelines and integrations | 4 |
| AP provisioning deployments | 4 |
| Catalyst controller migrations | 2 |
| Org create, clone and order-level inventory | 3 |
| Cellular uplink and geolocation settings | 2 |
| Own API keys and identity | 3 |
| Other organization-level reads | 6 |
Changelog
28 August 2026. Full revalidation against the Meraki GA API index. Removed five operation names that Cisco has since renamed or retired. Reorganised the list by dashboard area with plain-language setting names alongside the operation IDs. Added the sections above covering what is not backed up and why.
23 December 2025. Initial published coverage list.