DelineaSS

Delinea Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution.

Authentication & Identity Management · Delinea Secret Server

Details

IDDelineaSS
ProviderDelinea
CategoryAuthentication & Identity Management
From Version6.5.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution.
This integration was integrated and tested with version 5.0 of Delinea

Configure Delinea in Cortex

Parameter Description Required
url Server URL (e.g. https://example.net) True
credentials Username True
insecure Trust any certificate (not secure) False
proxy Use system proxy settings False
isFetchCredentials Fetches credentials False
credentialobjects List secret name for fetch credentials (separated by commas) False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

delinea-secret-password-get


Retrieved password from secret

Base Command

delinea-secret-password-get

Input

Argument Name Description Required
secret_id ID secret Required

Context Output

Path Type Description
Delinea.Secret.Password String Retrieved password from secret

Command Example

!delinea-secret-password-get secret_id=2

Context Example

{
    "Delinea": {
        "Secret": {
            "Password": "1234567890"
        }
    }
}

delinea-secret-username-get


Retrieved username from secret

Base Command

delinea-secret-username-get

Input

Argument Name Description Required
secret_id ID secret Required

Context Output

Path Type Description
Delinea.Secret.Username String Retrieved username from secret.

Command Example

!delinea-secret-username-get secret_id=2

Context Example

{
    "Delinea": {
        "Secret": {
            "Username": "w2\\w2"
        }
    }
}

delinea-secret-search-name


Search ID secret by field name

Base Command

delinea-secret-search-name

Input

Argument Name Description Required
search_name Search name secret. Required

Context Output

Path Type Description
Delinea.Secret.Id String Retrieved list ID for find secret by field secret name

Command Example

!delinea-secret-search-name search_name=xsoarSecret

Context Example

{
    "Delinea": {
        "Secret": {
            "Id": [
                5
            ]
        }
    }
}

delinea-secret-password-update


Update password for secret

Base Command

delinea-secret-password-update

Input

Argument Name Description Required
secret_id ID secret for update password Required
newpassword Value new password for secret Required

Context Output

Path Type Description
Delinea.Secret.Newpassword String New password changed for secret

Command Example

!delinea-secret-password-update secret_id=2 newpassword=12345

Context Example

{
    "Delinea": {
        "Secret": {
            "Newpassword": "12345"
        }
    }
}

delinea-secret-checkout


Check Out a secret

Base Command

delinea-secret-checkout

Input

Argument Name Description Required
secret_id ID secret for check out command Required

Context Output

Path Type Description
Delinea.Secret.Checkout String Return call command Check Out

Command Example

!delinea-secret-checkout secret_id=2

Context Example

{
    "Delinea": {
        "Secret": {
            "Checkout": {
            "responseCodes":null
            }
        }
    }
}

delinea-secret-checkin


Check In a secret

Base Command

delinea-secret-checkin

Input

Argument Name Description Required
secret_id Secret ID. Required

Context Output

Path Type Description
Delinea.Secret.Checkin String Secret object

Command Example

!delinea-secret-checkin secret_id=13

Context Example

{
    "Delinea": {
        "Secret": {
            "Checkin": {
                "active": true,
                "autoChangeEnabled": false,
                "checkOutEnabled": true,
                "checkedOut": false,
                "createDate": "2020-12-15T09:13:49.487",
                "daysUntilExpiration": null,
                "doubleLockEnabled": false,
                "extendedFields": null,
                "folderId": 3,
                "hidePassword": false,
                "id": 13,
                "inheritsPermissions": true,
                "isOutOfSync": false,
                "isRestricted": true,
                "lastAccessed": null,
                "lastHeartBeatStatus": "Pending",
                "lastPasswordChangeAttempt": "0001-01-01T00:00:00",
                "name": "secretT",
                "outOfSyncReason": "",
                "requiresApproval": false,
                "requiresComment": false,
                "responseCodes": null,
                "secretTemplateId": 6003,
                "secretTemplateName": "Windows Account",
                "siteId": 1
            }
        }
    }
}

delinea-folder-create


Create a new secret folder

Base Command

delinea-folder-create

Input

Argument Name Description Required
foldername Folder name Required
foldertypeid Folder type ID(1=< ID =< 3 Required
parentfolderid Parent folder ID Required
inheritPermissions Whether the folder should inherit permissions from its parent (default: true) Optional
inheritSecretPolicy Whether the folder should inherit the secret policy. Defaults to true unless creating a root folder. Optional
secretPolicyId Secret policy ID Optional

Context Output

Path Type Description
Delinea.Folder.Create Unknown New object folder

Command Example

!delinea-folder-create foldername="xsoarFolderTest" foldertypeid="1" parentfolderid="3"

Context Example

{
    "Delinea": {
        "Folder": {
            "Create": {
                "childFolders": null,
                "folderName": "xsoarFolderTest",
                "folderPath": "\\Personal Folders\\XSOAR integration\\xsoarFolderTest",
                "folderTypeId": 1,
                "id": 5,
                "inheritPermissions": false,
                "inheritSecretPolicy": false,
                "parentFolderId": 3,
                "secretPolicyId": -1,
                "secretTemplates": null
            }
        }
    }
}

delinea-folder-search


Search folder by name folder

Base Command

delinea-folder-search

Input

Argument Name Description Required
foldername Search name folder Required

Context Output

Path Type Description
Delinea.Folder.Id String Retrieved folder ID from search query

Command Example

!delinea-folder-search foldername="xsoarFolderTest"

Context Example

{
    "Delinea": {
        "Folder": {
            "Id": [
                5
            ]
        }
    }
}

Command Example

!delinea-folder-delete folder_id="18"

Context Example

{
    "Delinea": {
        "Folder": {
            "Delete": {
                "id": 18,
                "objectType": "Folder",
                "responseCodes": []
            }
        }
    }
}

delinea-secret-get


Get secret object by ID secret

Base Command

delinea-secret-get

Input

Argument Name Description Required
secret_id ID for secret Required

Context Output

Path Type Description
Delinea.Secret String Secret object

Command Example

!delinea-secret-get secret_id=2

Context Example

{
    "Delinea": {
        "Secret": {
            "accessRequestWorkflowMapId": -1,
            "active": true,
            "allowOwnersUnrestrictedSshCommands": false,
            "autoChangeEnabled": false,
            "autoChangeNextPassword": "2$C$7vl8*SN@",
            "checkOutChangePasswordEnabled": false,
            "checkOutEnabled": true,
            "checkOutIntervalMinutes": -1,
            "checkOutMinutesRemaining": 30,
            "checkOutUserDisplayName": "XSOAR integration",
            "checkOutUserId": 3,
            "checkedOut": true,
            "doubleLockId": -1,
            "enableInheritPermissions": true,
            "enableInheritSecretPolicy": true,
            "failedPasswordChangeAttempts": 0,
            "folderId": 3,
            "id": 2,
            "isDoubleLock": false,
            "isOutOfSync": false,
            "isRestricted": true,
            "items": [
                {
                    "fieldDescription": "The Server or Location of the Windows Machine.",
                    "fieldId": 83,
                    "fieldName": "Machine",
                    "fileAttachmentId": null,
                    "filename": null,
                    "isFile": false,
                    "isNotes": false,
                    "isPassword": false,
                    "itemId": 5,
                    "itemValue": "192.168.100.1",
                    "slug": "machine"
                },
                {
                    "fieldDescription": "The Username of the Windows User.",
                    "fieldId": 86,
                    "fieldName": "Username",
                    "fileAttachmentId": null,
                    "filename": null,
                    "isFile": false,
                    "isNotes": false,
                    "isPassword": false,
                    "itemId": 6,
                    "itemValue": "w2\\w2",
                    "slug": "username"
                },
                {
                    "fieldDescription": "The password of the Windows User.",
                    "fieldId": 85,
                    "fieldName": "Password",
                    "fileAttachmentId": null,
                    "filename": null,
                    "isFile": false,
                    "isNotes": false,
                    "isPassword": true,
                    "itemId": 7,
                    "itemValue": "1234567890",
                    "slug": "password"
                },
                {
                    "fieldDescription": "Any additional notes.",
                    "fieldId": 84,
                    "fieldName": "Notes",
                    "fileAttachmentId": null,
                    "filename": null,
                    "isFile": false,
                    "isNotes": true,
                    "isPassword": false,
                    "itemId": 8,
                    "itemValue": "",
                    "slug": "notes"
                }
            ],
            "lastHeartBeatCheck": "0001-01-01T00:00:00",
            "lastHeartBeatStatus": "Pending",
            "lastPasswordChangeAttempt": "0001-01-01T00:00:00",
            "launcherConnectAsSecretId": -1,
            "name": "test-w2",
            "outOfSyncReason": "",
            "passwordTypeWebScriptId": -1,
            "proxyEnabled": false,
            "requiresApprovalForAccess": false,
            "requiresComment": false,
            "responseCodes": [],
            "restrictSshCommands": false,
            "secretPolicyId": -1,
            "secretTemplateId": 6003,
            "secretTemplateName": "Windows Account",
            "sessionRecordingEnabled": false,
            "siteId": 1
        }
    }
}

delinea-secret-search


Search secret ID by multiply params

Base Command

delinea-secret-search

Input

Argument Name Description Required
filter.allowDoubleLocks Whether to allow DoubleLocks as part of the search. True by default Optional
filter.doNotCalculateTotal Whether to return the total number of secrets matching the filters. False by default Optional
filter.doubleLockId Only include Secrets with this DoubleLock ID assigned in the search results Optional
filter.extendedFields Names of Secret Template fields to return. Only exposed fields can be returned. Optional
filter.extendedTypeId Return only secrets matching a certain extended type Optional
filter.folderId Return only secrets within a certain folder Optional
filter.heartbeatStatus Return only secrets with a certain heartbeat status Optional
filter.includeActive Whether to include active secrets in results (when excluded equals true) Optional
filter.includeInactive Whether to include inactive secrets in results Optional
filter.includeRestricted Whether to include restricted secrets in results Optional
filter.isExactMatch Whether to do an exact match of the search text or a partial match Optional
filter.onlyRPCEnabled Whether to only include secrets whose template has Remote Password Changing enabled Optional
filter.onlySharedWithMe When true only Secrets where you are not the owner and the Secret was shared explicitly with your user id will be returned. Optional
filter.passwordTypeIds Return only secrets matching certain password types Optional
filter.permissionRequired Specify whether to filter by List, View, Edit, or Owner permission. Default is List. (List = 1, View = 2, Edit = 3, Owner = 4 Optional
filter.scope Specify whether to search AllSecrets, Recent, or Favorites (All = 1, Recent = 2,Favorites = 3 Optional
filter.searchField Field to search Optional
filter.searchFieldSlug Field-slug to search. This will override SearchField. Optional
filter.searchText Search text Optional
filter.secretTemplateId Return only secrets matching a certain template Optional
filter.siteId Return only secrets within a certain site Optional
skip Number of records to skip before taking results Optional
sortBy[0].direction Sort direction Optional
sortBy[0].name Sort field name Optional
sortBy[0].priority Priority index. Sorts with lower values are executed earlier Optional
take Maximum number of records to include in results Optional
filter.includeSubFolders Whether to include secrets in subfolders of the specified folder Optional

Context Output

Path Type Description
Delinea.Secret.Secret String Search secret object

Command Example

!delinea-secret-search filter_searchfields="username" filter_searchtext="xsoar"

Context Example

{
    "Delinea": {
        "Secret": {
            "Secret": [
                5
            ]
        }
    }
}

delinea-folder-update


Update a single secret folder by ID

Base Command

delinea-folder-update

Input

Argument Name Description Required
folderName Folder name Optional
folderTypeId Folder type ID Optional
id Folder ID. Must match ID in path Required
inheritPermissions Whether the folder inherits permissions from its parent Optional
inheritSecretPolicy Whether the folder inherits the secret policy Optional
parentFolderId ID parent folder Optional
secretPolicyId Secret Policy ID Optional

Context Output

Path Type Description
Delinea.Folder.Update String Retrieved return operation update folder

Command Example

!delinea-folder-update id=4 foldername="SafexsoarTest"

Context Example

{
    "Delinea": {
        "Folder": {
            "Update": {
                "childFolders": null,
                "folderName": "SafexsoarTest",
                "folderPath": "\\Personal Folders\\XSOAR integration\\SafexsoarTest",
                "folderTypeId": 1,
                "id": 4,
                "inheritPermissions": false,
                "inheritSecretPolicy": false,
                "parentFolderId": 3,
                "secretPolicyId": -1,
                "secretTemplates": null
            }
        }
    }
}

delinea-secret-create


Create new object Secret

Base Command

delinea-secret-create

Input

Argument Name Description Required
autoChangeEnabled AutoChangeEnabled options Optional
checkOutChangePasswordEnabled CheckOutChangePasswordEnabled options Optional
checkOutEnabled Whether secret checkout is enabled Optional
checkOutIntervalMinutes Checkout interval, in minutes (integer) Optional
enableInheritPermissions Whether the secret inherits permissions from the containing folder Optional
enableInheritSecretPolicy Whether the secret policy is inherited from the containing folder Optional
folderId Secret folder ID. May be null unless secrets are required to be in folders.(integer) Optional
launcherConnectAsSecretId LauncherConnectAsSecretId(integer) Optional
name Secret name Required
passwordTypeWebScriptId passwordTypeWebScriptId options(integer) Optional
proxyEnabled proxyEnabled options Optional
requiresCommen requiresCommen options Optional
secretPolicyId secretPolicyId options(integer) Optional
secretTemplateId Secret Template ID (integer) Required
sessionRecordingEnabled sessionRecordingEnabled options Optional
siteId siteId options (integer) Required
sshKeyArgs sshKeyArgs options(list args) Optional
domain_item Item Domain for secret. If need to select template. Optional
machine_item Item Machine for secret. If need to select template. Optional
username_item Item Username for secret.If need to select template. Optional
password_item Item Password for secret.If need to select template. Optional
notes_item Item Notes for secret.IF need to select template. Optional

Context Output

Path Type Description
Delinea.Secret.Create String Secret Model

Command Example

!delinea-secret-create name="xsoarSecret" secrettemplateid="6003" siteid="1" checkoutenabled=true folderid=3 machine_item="my-machine" username_item="my-username" password_item="XXXXXX@@@@@####"

Context Example

{
    "Delinea": {
        "Secret": {
            "Create": {
                "accessRequestWorkflowMapId": -1,
                "active": true,
                "allowOwnersUnrestrictedSshCommands": false,
                "autoChangeEnabled": false,
                "autoChangeNextPassword": null,
                "checkOutChangePasswordEnabled": false,
                "checkOutEnabled": true,
                "checkOutIntervalMinutes": -1,
                "checkOutMinutesRemaining": 0,
                "checkOutUserDisplayName": "",
                "checkOutUserId": 0,
                "checkedOut": false,
                "doubleLockId": 0,
                "enableInheritPermissions": true,
                "enableInheritSecretPolicy": false,
                "failedPasswordChangeAttempts": 0,
                "folderId": 3,
                "id": 5,
                "isDoubleLock": false,
                "isOutOfSync": false,
                "isRestricted": true,
                "items": [
                    {
                        "fieldDescription": "The Server or Location of the Windows Machine.",
                        "fieldId": 83,
                        "fieldName": "Machine",
                        "fileAttachmentId": null,
                        "filename": null,
                        "isFile": false,
                        "isNotes": false,
                        "isPassword": false,
                        "itemId": 19,
                        "itemValue": "my-machine",
                        "slug": "machine"
                    },
                    {
                        "fieldDescription": "The Username of the Windows User.",
                        "fieldId": 86,
                        "fieldName": "Username",
                        "fileAttachmentId": null,
                        "filename": null,
                        "isFile": false,
                        "isNotes": false,
                        "isPassword": false,
                        "itemId": 20,
                        "itemValue": "my-username",
                        "slug": "username"
                    },
                    {
                        "fieldDescription": "The password of the Windows User.",
                        "fieldId": 85,
                        "fieldName": "Password",
                        "fileAttachmentId": null,
                        "filename": null,
                        "isFile": false,
                        "isNotes": false,
                        "isPassword": true,
                        "itemId": 21,
                        "itemValue": "XXXXXX@@@@@####",
                        "slug": "password"
                    },
                    {
                        "fieldDescription": "Any additional notes.",
                        "fieldId": 84,
                        "fieldName": "Notes",
                        "fileAttachmentId": null,
                        "filename": null,
                        "isFile": false,
                        "isNotes": true,
                        "isPassword": false,
                        "itemId": 22,
                        "itemValue": "",
                        "slug": "notes"
                    }
                ],
                "lastHeartBeatCheck": "0001-01-01T00:00:00",
                "lastHeartBeatStatus": "Pending",
                "lastPasswordChangeAttempt": "0001-01-01T00:00:00",
                "launcherConnectAsSecretId": -1,
                "name": "xsoarSecret",
                "outOfSyncReason": "",
                "passwordTypeWebScriptId": -1,
                "proxyEnabled": false,
                "requiresApprovalForAccess": false,
                "requiresComment": false,
                "responseCodes": [],
                "restrictSshCommands": false,
                "secretPolicyId": -1,
                "secretTemplateId": 6003,
                "secretTemplateName": "Windows Account",
                "sessionRecordingEnabled": false,
                "siteId": 1
            }
        }
    }
}

delinea-secret-delete


Delete secret

Base Command

delinea-secret-delete

Input

Argument Name Description Required
id ID secret for delete Required

Context Output

Path Type Description
Delinea.Secret.Delete String Information about an object that was deleted

Command Example

!delinea-secret-delete id=2

Context Example

{
    "Delinea": {
        "Secret": {
            "Deleted": {
                "id": 2,
                "objectType": "Secret",
                "responseCodes": []
            }
        }
    }
}

delinea-secret-server-user-create


Create a new Secret Server user

Base Command

delinea-secret-server-user-create

Input

Argument Name Description Required
displayName User display name Required
password Password for new user Required
userName Username Required
adGuid Active Directory unique identifier Optional
domainId Active Directory domain ID Optional
duoTwoFactor Whether Duo two-factor authentication is enabled Optional
emailAddress User email address Optional
enabled Whether the user account is enabled Optional
fido2TwoFactor Whether Duo two-factor authentication is enabled Optional
isApplicationAccount IsApplicationAccount Optional
oathTwoFactor Whether OATH two-factor authentication is enabled Optional
radiusTwoFactor Whether RADIUS two-factor authentication is enabled Optional
radiusUserName RADIUS username Optional
twoFactor Whether two-factor authentication is enabled Optional

Context Output

Path Type Description
Delinea.Secret.Server.User.Create String User Model

Command Example

!delinea-secret-server-user-create displayname="UserOne" password="12345" username="UserOne"

Context Example

{
    "Delinea": {
        "User": {
            "Create": {
                "adAccountExpires":"0001-01-01T00:00:00",
                "adGuid":null,
                "created":"2022-06-01T08:31:15.275Z",
                "dateOptionId":-1,
                "displayName":"UserOne",
                "domainId":-1,
                "duoTwoFactor":false,
                "emailAddress":null,
                "enabled":true,
                "externalUserSource":"None",
                "fido2TwoFactor":false,
                "id":29,
                "ipAddressRestrictions":null,
                "isApplicationAccount":false,
                "isEmailCopiedFromAD":false,
                "isEmailVerified":false,
                "isLockedOut":false,
                "lastLogin":0001-01-01T00:00:00,
                "lastSessionActivity":null,
                "lockOutReason":null,
                "lockOutReasonDescription":null,
                "loginFailures":0,
                "mustVerifyEmail":false,
                "oathTwoFactor":false,
                "oathVerified":false,
                "passwordLastChanged":"0001-01-01T00:00:00",
                "personalGroupId":0,
                "radiusTwoFactor":false,
                "radiusUserName":null,
                "resetSessionStarted":"0001-01-01T00:00:00",
                "slackId":null,
                "timeOptionId":-1,
                "twoFactor":false,
                "unixAuthenticationMethod":Password,
                "userLcid":0,
                "userName":"UserOne",
                "verifyEmailSentDate":"0001-01-01T00:00:00"
            }
        }
    }
}

delinea-secret-server-user-search


Search, filter, sort, and page Secret Server users

Base Command

delinea-secret-server-user-search

Input

Argument Name Description Required
filter.domainId Filter users by Active Directory domain (integer) Optional
filter.includeInactive Whether to include inactive users in the results Optional
filter.searchFields Fields to search Optional
filter.searchText Search text Optional
skip Number of records to skip before taking results Optional
sortBy[0].direction Sort direction Optional
sortBy[0].name Sort field name Optional
sortBy[0].priority Priority index. Sorts with lower values are executed earlier (integer) Optional
take Maximum number of records to include in results(integer) Optional

Context Output

Path Type Description
Delinea.Secret.Server.User.Search String Specify paging and sorting options for querying records and returning results

Command Example

!delinea-secret-server-user-search filter_searchfields="userName" filter_searchtext="xsoarUser"

Context Example

{
    "Delinea": {
        "User": {
            "Search": null
        }
    }
}

delinea-secret-server-user-update


Update a single Secret Server user by ID

Base Command

delinea-secret-server-user-update

Input

Argument Name Description Required
id User ID Required
dateOptionId DateOptionId(integer) Optional
displayName Display name Optional
duoTwoFactor Whether Duo two-factor authentication is enabled Optional
emailAddress E-mail Optional
enabled Whether the user account is enabled Optional
fido2TwoFactor Whether FIDO2 two-factor authentication is enabled Optional
groupOwners GroupOwners(integer) Optional
isApplicationAccount IsApplicationAccount Optional
isGroupOwnerUpdate isGroupOwnerUpdate Optional
isLockedOut Whether the user is locked out Optional
loginFailures Number of login failures Optional
oathTwoFactor Whether OATH two-factor authentication is enabled Optional
password Password Optional
radiusTwoFactor Whether RADIUS two-factor authentication is enabled Optional
radiusUserName RADIUS username Optional
timeOptionId timeOptionId (integer) Optional
twoFactor Whether two-factor authentication is enabled Optional

Context Output

Path Type Description
Delinea.Secret.Server.User.Update String User Model

Command Example

!delinea-secret-server-user-update id=28 displayname="myTestUser"

Context Example

{
    "Delinea": {
        "User": {
            "Update": {
                "unixAuthenticationMethod":"Password",
                "enabled":true,
                "passwordLastChanged":"0001-01-01T00:00:00",
                "isEmailCopiedFromAD":false,
                "isApplicationAccount":false,
                "lockOutReason":null,
                "created":"2022-06-01T08:09:39",
                "radiusUserName":"UserOne",
                "radiusTwoFactor":false,
                "verifyEmailSentDate":"0001-01-01T00:00:00",
                "adAccountExpires":"0001-01-01T00:00:00",
                "slackId":null,
                "adGuid":null,
                "displayName":"myTestUser",
                "oathVerified":false,
                "lastSessionActivity":null,
                "externalUserSource":"None",
                "loginFailures":0,
                "lastLogin":"0001-01-01T00:00:00",
                "ipAddressRestrictions":null,
                "oathTwoFactor":false,
                "lockOutReasonDescription":null,
                "userName":"UserOne",
                "fido2TwoFactor":false,
                "emailAddress":null,
                "resetSessionStarted":"0001-01-01T00:00:00",
                "mustVerifyEmail":false,
                "isEmailVerified":false,
                "personalGroupId":0,
                "isLockedOut":false,
                "id":28,
                "twoFactor":false,
                "duoTwoFactor":false,
                "timeOptionId":-1,
                "userLcid":0,
                "dateOptionId":-1,
                "domainId":-1
            }
        }
    }
}

delinea-secret-server-user-delete


Delete a Secret Server user by ID

Base Command

delinea-secret-server-user-delete

Input

Argument Name Description Required
id User ID Required

Context Output

Path Type Description
Delinea.Secret.Server.User.Delete String Information about an object that was deleted

Command Example

!delinea-secret-server-user-delete id=5

Context Example

{
    "Delinea": {
        "User": {
            "Delete": {
                "id": 5,
                "objectType": "User",
                "responseCodes": null
            }
        }
    }
}

delinea-secret-server-user-get


Get Secret Server users list

Base Command

delinea-secret-server-user-get

Input

This command has no input arguments.

Context Output

Path Type Description
Delinea.Secret.Server.User String User object

Command Example


#### Context Example

```json
{
    "Delinea": {
        "Secret": {
            "Server": {
                "User": [
                    {
                        "id": 1,
                        "userName": "admin",
                        "displayName": "Administrator",
                        "enabled": true
                    }
                ]
            }
        }
    }
}

delinea-secret-rpc-changepassword


Change a secret’s password

Base Command

delinea-secret-rpc-changepassword

Input

Argument Name Description Required
secret_id Secret ID Required
newPassword New secret password Required

Context Output

Path Type Description
Delinea.Secret.ChangePassword String Secret summary object

Command Example

!delinea-secret-rpc-changepassword secret_id=4 newPassword="Test000"

Context Example

{
    "Delinea": {
        "Secret": {
            "ChangePassword": {
                "active": true,
                "autoChangeEnabled": false,
                "checkOutEnabled": false,
                "checkedOut": false,
                "createDate": "2020-11-02T18:06:07.357",
                "daysUntilExpiration": null,
                "doubleLockEnabled": false,
                "extendedFields": null,
                "folderId": -1,
                "hidePassword": false,
                "id": 4,
                "inheritsPermissions": false,
                "isOutOfSync": false,
                "isRestricted": false,
                "lastAccessed": null,
                "lastHeartBeatStatus": "Success",
                "lastPasswordChangeAttempt": "0001-01-01T00:00:00",
                "name": "g1-machine",
                "outOfSyncReason": "",
                "requiresApproval": false,
                "requiresComment": false,
                "responseCodes": null,
                "secretTemplateId": 6007,
                "secretTemplateName": "Unix Account (SSH)",
                "siteId": 1
            }
        }
    }
}

delinea-fetch-users


Fetch credentials from secret

Base Command

delinea-fetch-users

Input

NO input argumets

Context Output

Path Type Description
Delinea.User.Credentials String Secret credential objects

Command Example


#### Context Example

```json
[
    {
        "name": "4219",
        "password": "test3",
        "user": "test3"
    },
    {
        "name": "4217",
        "password": "dhPQhf1d@!E",
        "user": "secret2"
    }
]

delinea-platform-user-create


Create a new user in Platform

Base Command

delinea-platform-user-create

Input

Argument Name Description Required
MobileNumber The user mobile number. Optional
ID The UUID of the cloud user to change. Optional
InEverybodyRole The user is in the Everybody role? Optional
CmaRedirectedUserUuid The MFA redirected user UUID. Optional
OfficeNumber The user office number. Optional
ReportsTo The user reports to this user UUID. Optional
PreferredCulture The user preferred culture. Optional
DisplayName The user display. Optional
Password Password for new user. The password used to log in. Required
Name The user name. Required
AccountExp Account expires date/time. Optional
PasswordNeverExpire Does user’s password expire? Optional
Mail The User email. Optional
ServiceUser Whether this is a service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license. Optional
Description The User description. Optional
HomeNumber The user home number. Optional

Context Output

Path Type Description
Delinea.Platform.User.Create String Result

Command Example

!delinea-platform-user-create Password="Test@123" Name="uniquexsoar1" ServiceUser="true"

Context Example

{
    "Delinea": {
      "Platform" : {
          "User": {
              "Create": {
                  "Result": "a09eb441-f0a0-4894-a129-af4e0b3559d6",
                  "success": true,
                  "Message": null,
                  "MessageID": null,
                  "Exception": null,
                  "ErrorID": null,
                  "ErrorCode": null,
                  "IsSoftError": false,
                  "InnerExceptions": null
            }
          }
        }
      }
    }

delinea-platform-user-get


Get single Platform user by uuid

Base Command

delinea-platform-user-get

Input

Argument Name Description Required
userUuidOrUpn Fetches a Platform user by uuid or upn Required

Context Output

Path Type Description
Delinea.Platform.User.Get String User Model

Command Example

!delinea-platform-user-get userUuidOrUpn="09b9a9b0-6ce8-465f-ab03-65766d33b05e"

Context Example

{
    "Delinea": {
        "Platform": {
          "User": {
            "Get": {
                "directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
                "directoryServiceName": "Delinea",
                "directoryInstanceName": "Delinea",
                "uuid": "c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                "name": "admin@loud",
                "displayName": "admin",
                "state": "Active",
                "lastLogin": "2025-09-29T13:37:19.4639582Z",
                "lastInvite": "2025-04-16T17:38:47.0519372Z",
                "platformMembershipType": "Employee",
                "_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428440b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37we",
                "_links": {
                  "self": {
                    "href": "/api/users/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                    "method": "GET",
                    "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428440b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37we",
                    "title": "PlatformUser(Platform): admin"
                  },
                  "directory-users": [
                    {
                      "href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05R/users/c2c7bcc6-9560-44e0-8dff-5be221cd37e",
                      "method": "GET",
                      "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37we",
                      "title": "User(Delinea): admin"
                    }
                  ]
                }
            }
          }
        }
    }
}

delinea-platform-user-update


Update a single Platform user by ID

Base Command

delinea-platform-user-update

Input

Argument Name Description Required
MobileNumber The user mobile number. Optional
ID The UUID of the cloud user to change. Required
InEverybodyRole The user is in the Everybody role? Optional
CmaRedirectedUserUuid The MFA redirected user uuid. Optional
OfficeNumber The user office number. Optional
ReportsTo The user reports to this user UUID. Optional
PreferredCulture The user preferred culture. Optional
DisplayName The user display. Optional
Password Password for new user. The password used to log in. Optional
Name The user name. Optional
AccountExp Account expires date/time. Optional
PasswordNeverExpire Does user’s password expire? Optional
Mail The User email. Optional
ServiceUser Whether this is a service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license. Optional
Description The User description. Optional
HomeNumber The user home number. Optional

Context Output

Path Type Description
Delinea.Platform.User.Update String User is successfully updated then returning success: true in result

Command Example

!delinea-platform-user-update ID="b02319fc-b26a-4352-8e4e-d8ea1188f160" Name="xsoarUserTest1"

Context Example

{
    "Delinea": {
        "Platform": {
            "User": {
                "Update": {
                  "success": true,
                  "Result": null,
                  "Message": null,
                  "MessageID": null,
                  "Exception": null,
                  "ErrorID": null,
                  "ErrorCode": null,
                  "IsSoftError": false,
                  "InnerExceptions": null
               }
            }
        }
    }
}

delinea-platform-user-delete


Delete a Platform user by UUID or Name

Base Command

delinea-platform-user-delete

Input

Argument Name Description Required
id User UUID Required

Context Output

Path Type Description
Delinea.Platform.User.Delete String Information about an object that was deleted and returning success: true in result

Command Example

!delinea-platform-user-delete id="a09eb441-f0a0-4894-a129-af4e0b3559d6"

Context Example

{
    "Delinea": {
        "Platform": {
            "User": {
                "Delete": {
                  "success": true,
                  "Result": null,
                  "Message": null,
                  "MessageID": null,
                  "Exception": null,
                  "ErrorID": null,
                  "ErrorCode": null,
                  "IsSoftError": false,
                  "InnerExceptions": null
               }
            }
        }
    }
}

delinea-platform-get-all-users


Get single Platform user by uuid

Base Command

delinea-platform-get-all-users

Input

Argument Name Description Required
filter_displayName Display name to filter users. Optional
pageSize Page size. Default 1000. Optional

Context Output

Path Type Description
Delinea.Platform.Users String Returning users based on pageSize and default page size is 1000

Command Example

!delinea-platform-get-all-users pageSize="1"

Context Example

{
    "Delinea": {
        "Platform": {
            "Get" : {
                "All" : {
                    "Users": {
                        "users": [
                          {
                            "directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
                            "directoryServiceName": "Delinea",
                            "directoryInstanceName": "Delinea",
                            "uuid": "c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                            "name": "cloudadmin@cloud",
                            "displayName": "cloudadmin",
                            "state": "Active",
                            "lastLogin": "2025-09-29T13:37:19.4639582Z",
                            "lastInvite": "2025-04-16T17:38:47.0519372Z",
                            "platformMembershipType": "Employee",
                            "_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                            "_links": {
                              "self": {
                                "href": "/api/users/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                                "method": "GET",
                                "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                                "title": "PlatformUser(Platform): cloudadmin"
                              },
                              "directory-users": [
                                {
                                  "href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05E/users/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                                  "method": "GET",
                                  "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
                                  "title": "User(Delinea): cloudadmin"
                                }
                              ]
                            }
                          }
                        ]
                    }
                }
            }
        }
    }
}

delinea-platform-get-user-search-by-text


Get Platform users search by Text

Base Command

delinea-platform-get-user-search-by-text

Input

Argument Name Description Required
filter.searchText Search Text is looked for in multiple fields Required

Context Output

Path Type Description
Delinea.Platform.UserSearchResults String SearchText is looked for in multiple fields and returning results

Command Example

!delinea-platform-get-user-search-by-text filter.searchText="sail"

Context Example

{
    "Delinea": {
        "Platform": {
            "Get" : {
                "User" : {
                    "Searchbytext": {
                        "users": [
                          {
                            "directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
                            "directoryServiceName": "Delinea",
                            "directoryInstanceName": "Delinea",
                            "uuid": "3f4b80c0-c853-473f-9534-66e4a8331843",
                            "name": "ren@cloud",
                            "displayName": "sailpoint+user.service",
                            "state": "Created",
                            "platformMembershipType": "Employee",
                            "_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/3f4b80c0-c853-473f-9534-66e4a8331843",
                            "_links": {
                              "self": {
                                "href": "/api/users/3f4b80c0-c853-473f-9534-66e4a8331843",
                                "method": "GET",
                                "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/3f4b80c0-c853-473f-9534-66e4a8331843",
                                "title": "PlatformUser(Platform): sailpoint+user.service"
                              },
                              "directory-users": [
                                {
                                  "href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05E/users/3f4b80c0-c853-473f-9534-66e4a8331843",
                                  "method": "GET",
                                  "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/3f4b80c0-c853-473f-9534-66e4a8331843",
                                  "title": "User(Delinea): sailpoint+user.service"
                                }
                              ]
                            }
                          },
                          {
                            "directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
                            "directoryServiceName": "Delinea",
                            "directoryInstanceName": "Delinea",
                            "uuid": "b977dd7d-b771-40b6-83f3-f04154a733c5",
                            "name": "roderick@cloud",
                            "displayName": "roderick",
                            "state": "Active",
                            "lastLogin": "2025-08-28T17:52:02.0344759Z",
                            "platformMembershipType": "Employee",
                            "_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/b977dd7d-b771-40b6-83f3-f04154a733c5",
                            "_links": {
                              "self": {
                                "href": "/api/users/b977dd7d-b771-40b6-83f3-f04154a733c5",
                                "method": "GET",
                                "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/b977dd7d-b771-40b6-83f3-f04154a733c5",
                                "title": "PlatformUser(Platform): roderick"
                              },
                              "directory-users": [
                                {
                                  "href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05E/users/b977dd7d-b771-40b6-83f3-f04154a733c5",
                                  "method": "GET",
                                  "drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/b977dd7d-b771-40b6-83f3-f04154a733c5",
                                  "title": "User(Delinea): roderick"
                                }
                              ]
                            }
                          }
                        ]
                    }
                }
            }
        }
    }
}

Configuration parameters

  • url — Server URL (e.g. https://example.net) (required)
  • credentials — Username (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • isFetchCredentials — Fetches Credentials
  • secrets — Secret IDs (Provide multiple Id's by using ',' example- 1,2,3)

Commands (26)

  • delinea-folder-create

    Create a new folder.

  • delinea-folder-delete

    Delete a folder by folder ID.

  • delinea-folder-search

    Search a specific folder by name.

  • delinea-folder-update

    Update a single secret folder by ID.

  • delinea-platform-get-all-users

    Fetch all users from the platform.

  • delinea-platform-get-user-search-by-text

    List of platform users matching search text.

  • delinea-platform-user-create

    Create a new user in Platform.

  • delinea-platform-user-delete

    Delete Platform user by ID.

  • delinea-platform-user-get

    Fetch a Platform user by uuid or upn.

  • delinea-platform-user-update

    Update a Platform user by ID.

  • delinea-secret-checkin

    Check in a secret.

  • delinea-secret-checkout

    Check out a secret.

  • delinea-secret-create

    Create a new secret.

  • delinea-secret-delete

    Delete secret by id.

  • delinea-secret-get

    Get secret object by secret ID.

  • delinea-secret-password-get

    Extracting the password field from the required secret.

  • delinea-secret-password-update

    Update password for a secret by ID.

  • delinea-secret-rpc-changepassword

    Remote password changing.

  • delinea-secret-search

    Search secret by multiply parameters.

  • delinea-secret-search-name

    Search for a secret using secret name.

  • delinea-secret-server-user-create

    Create a new user in Secret Server.

  • delinea-secret-server-user-delete

    Delete Secret Server user by ID.

  • delinea-secret-server-user-get

    Get Secret Server users list.

  • delinea-secret-server-user-search

    User search, filter and sort in Secret Server.

  • delinea-secret-server-user-update

    Update a single user by ID in Secret Server.

  • delinea-secret-username-get

    Extracting the username field from the required secret.

category: Authentication & Identity Management
provider: Delinea
sectionorder:
- Connect
commonfields:
  id: DelineaSS
  version: -1
configuration:
- display: Server URL (e.g. https://example.net)
  name: url
  required: true
  type: 0
  section: Connect
- display: Username
  name: credentials
  required: true
  type: 9
  section: Connect
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
  section: Connect
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
  section: Connect
- display: Fetches Credentials
  name: isFetchCredentials
  type: 8
  required: false
  section: Connect
- display: Secret IDs (Provide multiple Id's by using ',' example- 1,2,3)
  name: secrets
  type: 12
  required: false
  section: Connect
description: Delinea Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution.
display: DelineaSS
name: DelineaSS
script:
  commands:
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    - description: Notes to get the password.
      name: autoComment
    description: Extracting the password field from the required secret.
    name: delinea-secret-password-get
    outputs:
    - contextPath: Delinea.Secret.Password
      description: Password from secret.
      type: String
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    description: Extracting the username field from the required secret.
    name: delinea-secret-username-get
    outputs:
    - contextPath: Delinea.Secret.Username
      description: Username from secret.
      type: String
  - arguments:
    - description: Search for secret using secret name.
      name: search_name
      required: true
    description: Search for a secret using secret name.
    name: delinea-secret-search-name
    outputs:
    - contextPath: Delinea.Secret.Id
      description: List of Secret IDs.
      type: String
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    - description: New password value.
      name: newpassword
      required: true
      secret: true
    - description: Notes to update the password.
      name: autoComment
    description: Update password for a secret by ID.
    name: delinea-secret-password-update
    outputs:
    - contextPath: Delinea.Secret.Newpassword
      description: New password changed for secret.
      type: String
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    description: Check out a secret.
    name: delinea-secret-checkout
    outputs:
    - contextPath: Delinea.Secret.Checkout
      description: Returns response (None = Successful).
      type: String
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    description: Check in a secret.
    name: delinea-secret-checkin
    outputs:
    - contextPath: Delinea.Secret.Checkin
      description: Secret object.
      type: String
  - arguments:
    - description: Name for new folder.
      name: foldername
      required: true
    - defaultValue: '1'
      description: Folder type ID, 1 - for folder.
      name: foldertypeid
      predefined:
      - ''
      required: true
    - description: Parent folder ID.
      name: parentfolderid
      required: true
    - auto: PREDEFINED
      description: 'Whether the folder should inherit permissions from its parent (default: true).'
      name: inheritpermissions
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the folder should inherit the secret policy. Defaults to true unless creating a root folder.
      name: inheritsecretpolicy
      predefined:
      - 'true'
      - 'false'
    - description: Secret policy ID.
      name: secretpolicyid
    description: Create a new folder.
    name: delinea-folder-create
    outputs:
    - contextPath: Delinea.Folder.Create
      description: New object folder.
      type: String
  - arguments:
    - description: Search folder name.
      name: foldername
      required: true
    description: Search a specific folder by name.
    name: delinea-folder-search
    outputs:
    - contextPath: Delinea.Folder.Id
      description: List of Folder IDs.
      type: String
  - arguments:
    - description: Folder ID.
      name: folder_id
      required: true
    description: Delete a folder by folder ID.
    name: delinea-folder-delete
    outputs:
    - contextPath: Delinea.Folder.Delete
      description: Folder ID.
      type: String
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    - description: Notes to get a secret.
      name: autoComment
    description: Get secret object by secret ID.
    name: delinea-secret-get
    outputs:
    - contextPath: Delinea.Secret
      description: Secret object.
      type: String
  - arguments:
    - auto: PREDEFINED
      description: Whether to allow DoubleLocks as part of the search. True by default.
      name: filter_allowdoublelocks
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether to return the total number of secrets matching the filters. False by default.
      name: filter_donotcalculatetotal
      predefined:
      - 'true'
      - 'false'
    - description: Only include Secrets with this DoubleLock ID assigned in the search results.
      name: filter_doublelockid
    - description: Names of Secret Template fields to return. Only exposed fields can be returned.
      name: filter_extendedfields
    - description: Return only secrets matching a certain extended type.
      name: filter_extendedtypeid
    - description: Return only secrets within a certain folder.
      name: filter_folderid
    - description: Return only secrets with a certain heartbeat status.
      name: filter_heartbeatstatus
    - auto: PREDEFINED
      description: Whether to include active secrets in results (when excluded equals true).
      name: filter_includeactive
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether to include inactive secrets in results.
      name: filter_includeinactive
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: "Whether to include restricted secrets in results."
      name: filter_includerestricted
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether to do an exact match of the search text or a partial match.
      name: filter_isexactmatch
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether to only include secrets whose template has Remote Password Changing enabled.
      name: filter_onlyrpcenabled
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: When true only Secrets where you are not the owner and the Secret was shared explicitly with your user id will be returned.
      name: filter_onlysharedwithme
      predefined:
      - 'true'
      - 'false'
    - description: Return only secrets matching certain password types.
      name: filter_passwordtypelds
    - auto: PREDEFINED
      description: Specify whether to filter by List, View, Edit, or Owner permission. Default is List. (List = 1, View = 2, Edit = 3, Owner = 4).
      name: filter_permissionrequired
      predefined:
      - '1'
      - '2'
      - '3'
      - '4'
    - auto: PREDEFINED
      description: Specify whether to search AllSecrets, Recent, or Favorites (All = 1, Recent = 2, Favorites = 3).
      name: filter_scope
      predefined:
      - '1'
      - '2'
      - '3'
    - description: Field to search.
      name: filter_searchfield
    - description: Field-slug to search. This will override SearchField.
      name: filter_searchfieldslug
    - description: Search text.
      name: filter_searchtext
    - description: Return only secrets matching a certain template.
      name: filter_secrettemplateid
    - description: Return only secrets within a certain site.
      name: filter_siteid
    - description: Number of records to skip before taking results.
      name: skip
    - description: Sort direction.
      name: sortBy_direction
    - description: Sort field name.
      name: sortBy_name
    - description: Priority index. Sorts with lower values are executed earlier.
      name: sortBy_priority
    - description: Maximum number of records to include in results.
      name: take
    - auto: PREDEFINED
      description: Whether to include secrets in subfolders of the specified folder.
      name: filter_includesubfolders
      predefined:
      - 'true'
      - 'false'
    description: Search secret by multiply parameters.
    name: delinea-secret-search
    outputs:
    - contextPath: Delinea.Secret.Secret
      description: List of Folder IDs.
      type: String
  - arguments:
    - description: Folder name.
      name: foldername
    - description: Folder type ID.
      name: foldertypeid
    - description: Folder ID. Must match ID in path.
      name: id
      required: true
    - auto: PREDEFINED
      description: Whether the folder inherits permissions from its parent.
      name: inheritpermissions
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the folder inherits the secret policy.
      name: inheritsecretpolicy
      predefined:
      - 'true'
      - 'false'
    - description: ID parent folder.
      name: parentfolderid
    - description: Secret Policy ID.
      name: secretpolicyid
    description: Update a single secret folder by ID.
    name: delinea-folder-update
    outputs:
    - contextPath: Delinea.Folder.Update
      description: Folder object.
      type: String
  - arguments:
    - auto: PREDEFINED
      description: Whether the secret’s password is automatically rotated on a schedule.
      name: autochangeenabled
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the secret’s password is automatically changed when a secret is checked in. This is a security feature that prevents a use of the password retrieved from check-out after the secret is checked in.
      name: checkoutchangepasswordenabled
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the user must check-out the secret to view it. Checking out gives the user exclusive access to the secret for a specified period or until the secret is checked in.
      name: checkoutenabled
      predefined:
      - 'true'
      - 'false'
    - description: The number of minutes that a secret will remain checked out.
      name: checkoutintervalminutes
    - auto: PREDEFINED
      description: Whether the secret inherits permissions from the containing folder.
      name: enableinheritpermissions
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the secret policy is inherited from the containing folder.
      name: enableinheritsecretpolicy
      predefined:
      - 'true'
      - 'false'
    - description: Secret folder ID. If the secret is contained in a folder, the id of the containing folder. Use -1 for secrets that are in the root folder.
      name: folderid
    - description: When an SSH secret is proxied, you can choose to connect as another user and then do an su to the current secret’s user. This is a common practice for connecting with a lower privileged account and then switching to the root user.
      name: launcherconnectassecretid
    - description: Secret name.
      name: name
      required: true
    - description: The id of the password change script to use on applicable web password secrets.
      name: passwordtypewebscriptld
    - auto: PREDEFINED
      description: Whether the user must enter a comment to view the secret.
      name: requirescommen
      predefined:
      - 'true'
      - 'false'
    - description: The id of the secret policy that controls the security and other settings of the secret.
      name: secretpolicyid
    - description: Secret Template ID (integer).
      name: secrettemplateid
      required: true
    - auto: PREDEFINED
      description: Whether session recording is enabled.
      name: sessionrecordingenabled
      predefined:
      - 'true'
      - 'false'
    - defaultValue: '1'
      description: The id of the distributed engine site that is used by this secret for operations such as password changing.
      name: siteid
    - description: |-
        sshKeyArgs options. generateSshKeys (bool) – Whether to generate an SSH private key.
        generatePassphrase (bool) – Whether to generate an SSH private key passphrase. Only applicable when the Secret template has a password changer with the Private Key Passphrase field mapped. If it is not mapped, this setting is ignored.
      name: sshkeyargs
    - description: Item Domain for secret. If need to select template.
      name: domain_item
    - description: Item Machine for secret. If need to select template.
      name: machine_item
    - description: Item Username for secret. If need to select template.
      name: username_item
    - description: Item Password for secret. If need to select template.
      name: password_item
    - description: Item Notes for secret. If need to select template.
      name: notes_item
    - auto: PREDEFINED
      description: Whether the secret should be flagged for immediate password change.
      name: autochangenextpassword
      predefined:
      - 'true'
      - 'false'
    - description: The id of the mapping entity that associates this secret to a specific access request workflow.
      name: accessRequestWorkflowMapId
    description: Create a new secret.
    name: delinea-secret-create
    outputs:
    - contextPath: Delinea.Secret.Create
      description: Secret object.
      type: String
  - arguments:
    - description: ID secret for delete.
      name: id
      required: true
    - description: Notes to Delete the secret.
      name: autoComment
    description: Delete secret by id.
    name: delinea-secret-delete
    outputs:
    - contextPath: Delinea.Secret.Delete
      description: Secret object.
      type: String
  - arguments:
    - description: The user's name as displayed in the user interface.
      name: displayname
      required: true
    - description: Password for new user. The password used to log in.
      name: password
      required: true
    - description: Username.
      name: username
      required: true
    - description: Active Directory unique identifier.
      name: adguid
    - description: Active Directory domain ID.
      name: domainid
    - auto: PREDEFINED
      description: Whether Duo two-factor authentication is enabled.
      name: duotwofactor
      predefined:
      - 'true'
      - 'false'
    - description: The user's email address. Used by the system to send reports, access requests, and other notifications.
      name: emailaddress
    - auto: PREDEFINED
      defaultValue: 'true'
      description: Whether the user account is enabled. Disabled users are unable to log in and do not consume a user license.
      name: enabled
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether FIDO2 two-factor authentication is enabled.
      name: fido2twofactor
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether this is an application account. Application accounts are used for automation, cannot log in using the UI, and do not consume a user license.
      name: isapplicationaccount
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether OATH two-factor authentication is enabled.
      name: oathtwofactor
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether RADIUS two-factor authentication is enabled.
      name: radiustwofactor
      predefined:
      - 'true'
      - 'false'
    - description: When a user account uses RADIUS two-factor authentication, this property is the user name of the RADIUS account used to authenticate this user.
      name: radiususername
    - auto: PREDEFINED
      description: Whether two-factor authentication is enabled.
      name: twofactor
      predefined:
      - 'true'
      - 'false'
    description: Create a new user in Secret Server.
    name: delinea-secret-server-user-create
    outputs:
    - contextPath: Delinea.Secret.Server.User.Create
      description: User object.
      type: String
    compliantpolicies:
    - User Hard Remediation
  - arguments:
    - description: Filter users by Active Directory domain (integer).
      name: filter_domainid
    - auto: PREDEFINED
      description: Whether to include inactive users in the results.
      name: filter_includeinactive
      predefined:
      - 'true'
      - 'false'
    - description: Fields to search.
      name: filter_searchfields
    - description: Search text.
      name: filter_searchtext
    - description: Number of records to skip before taking results.
      name: skip
    - description: Sort direction.
      name: sortBy_direction
    - description: Sort field name.
      name: sortBy_name
    - description: Priority index. Sorts with lower values are executed earlier (integer).
      name: sortBy_priority
    - description: Maximum number of records to include in results (integer).
      name: take
    description: User search, filter and sort in Secret Server.
    name: delinea-secret-server-user-search
    outputs:
    - contextPath: Delinea.Secret.Server.User.Search
      description: List of User IDs.
      type: String
  - arguments:
    - description: User ID. Must match ID in path.
      name: id
      required: true
    - description: The id of the date format to use when displaying dates to this user. These options are defined in Admin > Configuration.
      name: dateoptionid
    - description: The user's name as displayed in the user interface.
      name: displayname
    - auto: PREDEFINED
      description: Whether Duo two-factor authentication is enabled.
      name: duotwofactor
      predefined:
      - 'true'
      - 'false'
    - description: The user's email address. Used by the system to send reports, access requests, and other notifications.
      name: emailaddress
    - auto: PREDEFINED
      description: Whether the user account is enabled. Disabled users are unable to log in and do not consume a user license.
      name: enabled
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether FIDO2 two-factor authentication is enabled.
      name: fido2twofactor
      predefined:
      - 'true'
      - 'false'
    - description: A list of group ids for the groups that can manage this user.
      name: groupowners
    - auto: PREDEFINED
      description: Whether this is an application account. Application accounts are used for automation, cannot log in using the UI, and do not consume a user license.
      name: isapplicationaccount
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the user is managed by the groups specified in GroupOwners or is managed by all users with the 'Administer Users' role permission.
      name: isgroupownerupdate
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Whether the user is locked out.
      name: isLockedout
      predefined:
      - 'true'
      - 'false'
    - description: Number of login failures to allow before the account is locked out. Set to 0 for unlimited login attempts.
      name: loginfailures
    - auto: PREDEFINED
      description: Whether OATH two-factor authentication is enabled.
      name: oathtwofactor
      predefined:
      - 'true'
      - 'false'
    - description: Password for update user. The password used to log in.
      name: password
    - auto: PREDEFINED
      description: Whether RADIUS two-factor authentication is enabled.
      name: radiustwofactor
      predefined:
      - 'true'
      - 'false'
    - description: When a user account uses RADIUS two-factor authentication, this property is the user name of the RADIUS account used to authenticate this user.
      name: radiususername
    - description: The id of the time format to use when displaying times to this user. These options are defined in Admin > Configuration.
      name: timeoptionid
    - auto: PREDEFINED
      description: Whether two-factor authentication is enabled.
      name: twofactor
      predefined:
      - 'true'
      - 'false'
    - auto: PREDEFINED
      description: Determines the type of Unix authentication to use. Must be Password (0), PublicKey (1), PasswordOrPublicKey (2), or PasswordAndPublicKey (3).
      name: unixauthenticationmethodtype
      predefined:
      - '0'
      - '1'
      - '2'
      - '3'
    description: Update a single user by ID in Secret Server.
    name: delinea-secret-server-user-update
    outputs:
    - contextPath: Delinea.Secret.Server.User.Update
      description: User object.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: User ID.
      name: id
      required: true
    description: Delete Secret Server user by ID.
    name: delinea-secret-server-user-delete
    outputs:
    - contextPath: Delinea.Secret.Server.User.Delete
      description: User object.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments: []
    description: Get Secret Server users list.
    execution: false
    name: delinea-secret-server-user-get
    outputs:
    - contextPath: Delinea.Secret.Server.User
      description: User object.
      type: String
    compliantpolicies:
    - User Hard Remediation
  - arguments:
    - description: Secret ID.
      name: secret_id
      required: true
    - description: The new password.
      name: newpassword
      required: true
    - description: Notes to change the password.
      name: autoComment
    description: Remote password changing.
    name: delinea-secret-rpc-changepassword
    outputs:
    - contextPath: Delinea.Secret.ChangePassword
      description: Secret summary.
      type: String
  - arguments:
    - description: Mobile number of the user.
      name: MobileNumber
    - description: The UUID of the cloud user to change.
      name: ID
    - description: The user is in the Everybody role?
      name: InEverybodyRole
      predefined:
        - 'true'
        - 'false'
    - description: The MFA redirected user uuid.
      name: CmaRedirectedUserUuid
    - description: The user office number.
      name: OfficeNumber
    - description: The user reports to this user UUID.
      name: ReportsTo
    - description: The user preferred culture.
      name: PreferredCulture
    - description: The user display.
      name: DisplayName
    - description: Password for new user. The password used to log in.
      name: Password
      required: true
    - description: The user name.
      name: Name
      required: true
    - description: Account expires date/time.
      name: AccountExp
    - description: Does user's password expire?
      name: PasswordNeverExpire
      predefined:
        - 'true'
        - 'false'
    - description: The User email.
      name: Mail
    - description: Whether this is an service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license.
      name: ServiceUser
      predefined:
        - 'true'
        - 'false'
    - description: The User description.
      name: Description
    - description: The user home number.
      name: HomeNumber
    description: Create a new user in Platform.
    name: delinea-platform-user-create
    outputs:
    - contextPath: Delinea.Platform.User.Create
      description: User object.
      type: String
  - arguments:
    - description: The name or UUID of the user to remove.
      name: id
      required: true
    description: Delete Platform user by ID.
    name: delinea-platform-user-delete
    outputs:
      - contextPath: Delinea.Platform.User.Delete
        description: User object.
        type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
      - description: Mobile number of the user.
        name: MobileNumber
      - description: The UUID of the cloud user to change.
        name: ID
        required: true
      - description: The user is in the Everybody role?
        name: InEverybodyRole
        predefined:
          - 'true'
          - 'false'
      - description: The MFA redirected user uuid.
        name: CmaRedirectedUserUuid
      - description: The user office number.
        name: OfficeNumber
      - description: The user reports to this user UUID.
        name: ReportsTo
      - description: The user preferred culture.
        name: PreferredCulture
      - description: The user display .
        name: DisplayName
      - description: Password for new user. The password used to log in.
        name: Password
      - description: The user name.
        name: Name
      - description: Account expires date/time.
        name: AccountExp
      - description: Does user's password expire?
        name: PasswordNeverExpire
        predefined:
          - 'true'
          - 'false'
      - description: The User email.
        name: Mail
      - description: Whether this is an service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license.
        name: ServiceUser
        predefined:
          - 'true'
          - 'false'
      - description: The User description.
        name: Description
      - description: The user home number.
        name: HomeNumber
    description: Update a Platform user by ID.
    name: delinea-platform-user-update
    outputs:
      - contextPath: Delinea.Platform.User.Update
        description: User object.
        type: String
  - arguments:
    - description: Fetches a platform user by uuid or upn (User Principal Name).
      name: userUuidOrUpn
      required: true
    description: Fetch a Platform user by uuid or upn.
    name: delinea-platform-user-get
    outputs:
    - contextPath: Delinea.Platform.User.Get
      description: User object.
      type: String
  - arguments:
    - description: Display name to filter users.
      name: filter_displayName
      required: false
    - description: Page size. Default 1000.
      name: pageSize
      required: false
    description: Fetch all users from the platform.
    name: delinea-platform-get-all-users
    outputs:
      - contextPath: Delinea.Platform.Users
        description: User object.
        type: String
  - arguments:
      - description: SearchText is looked for in multiple fields.
        name: filter.searchText
        required: true
      - description: Page size. Default 1000.
        name: pageSize
    description: List of platform users matching search text.
    name: delinea-platform-get-user-search-by-text
    outputs:
      - contextPath: Delinea.Platform.UserSearchResults
        description: User object.
        type: String
  dockerimage: demisto/python3:3.12.13.10116658
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- No tests (auto formatted)
fromversion: 6.5.0