DelineaSS
Delinea Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution.
Authentication & Identity Management · Delinea Secret Server
Details
| ID | DelineaSS |
|---|---|
| Provider | Delinea |
| Category | Authentication & Identity Management |
| From Version | 6.5.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution.
This integration was integrated and tested with version 5.0 of Delinea
Configure Delinea in Cortex
| Parameter | Description | Required |
|---|---|---|
| url | Server URL (e.g. https://example.net) | True |
| credentials | Username | True |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
| isFetchCredentials | Fetches credentials | False |
| credentialobjects | List secret name for fetch credentials (separated by commas) | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
delinea-secret-password-get
Retrieved password from secret
Base Command
delinea-secret-password-get
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | ID secret | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Password | String | Retrieved password from secret |
Command Example
!delinea-secret-password-get secret_id=2
Context Example
{
"Delinea": {
"Secret": {
"Password": "1234567890"
}
}
}
delinea-secret-username-get
Retrieved username from secret
Base Command
delinea-secret-username-get
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | ID secret | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Username | String | Retrieved username from secret. |
Command Example
!delinea-secret-username-get secret_id=2
Context Example
{
"Delinea": {
"Secret": {
"Username": "w2\\w2"
}
}
}
delinea-secret-search-name
Search ID secret by field name
Base Command
delinea-secret-search-name
Input
| Argument Name | Description | Required |
|---|---|---|
| search_name | Search name secret. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Id | String | Retrieved list ID for find secret by field secret name |
Command Example
!delinea-secret-search-name search_name=xsoarSecret
Context Example
{
"Delinea": {
"Secret": {
"Id": [
5
]
}
}
}
delinea-secret-password-update
Update password for secret
Base Command
delinea-secret-password-update
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | ID secret for update password | Required |
| newpassword | Value new password for secret | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Newpassword | String | New password changed for secret |
Command Example
!delinea-secret-password-update secret_id=2 newpassword=12345
Context Example
{
"Delinea": {
"Secret": {
"Newpassword": "12345"
}
}
}
delinea-secret-checkout
Check Out a secret
Base Command
delinea-secret-checkout
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | ID secret for check out command | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Checkout | String | Return call command Check Out |
Command Example
!delinea-secret-checkout secret_id=2
Context Example
{
"Delinea": {
"Secret": {
"Checkout": {
"responseCodes":null
}
}
}
}
delinea-secret-checkin
Check In a secret
Base Command
delinea-secret-checkin
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | Secret ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Checkin | String | Secret object |
Command Example
!delinea-secret-checkin secret_id=13
Context Example
{
"Delinea": {
"Secret": {
"Checkin": {
"active": true,
"autoChangeEnabled": false,
"checkOutEnabled": true,
"checkedOut": false,
"createDate": "2020-12-15T09:13:49.487",
"daysUntilExpiration": null,
"doubleLockEnabled": false,
"extendedFields": null,
"folderId": 3,
"hidePassword": false,
"id": 13,
"inheritsPermissions": true,
"isOutOfSync": false,
"isRestricted": true,
"lastAccessed": null,
"lastHeartBeatStatus": "Pending",
"lastPasswordChangeAttempt": "0001-01-01T00:00:00",
"name": "secretT",
"outOfSyncReason": "",
"requiresApproval": false,
"requiresComment": false,
"responseCodes": null,
"secretTemplateId": 6003,
"secretTemplateName": "Windows Account",
"siteId": 1
}
}
}
}
delinea-folder-create
Create a new secret folder
Base Command
delinea-folder-create
Input
| Argument Name | Description | Required |
|---|---|---|
| foldername | Folder name | Required |
| foldertypeid | Folder type ID(1=< ID =< 3 | Required |
| parentfolderid | Parent folder ID | Required |
| inheritPermissions | Whether the folder should inherit permissions from its parent (default: true) | Optional |
| inheritSecretPolicy | Whether the folder should inherit the secret policy. Defaults to true unless creating a root folder. | Optional |
| secretPolicyId | Secret policy ID | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Folder.Create | Unknown | New object folder |
Command Example
!delinea-folder-create foldername="xsoarFolderTest" foldertypeid="1" parentfolderid="3"
Context Example
{
"Delinea": {
"Folder": {
"Create": {
"childFolders": null,
"folderName": "xsoarFolderTest",
"folderPath": "\\Personal Folders\\XSOAR integration\\xsoarFolderTest",
"folderTypeId": 1,
"id": 5,
"inheritPermissions": false,
"inheritSecretPolicy": false,
"parentFolderId": 3,
"secretPolicyId": -1,
"secretTemplates": null
}
}
}
}
delinea-folder-search
Search folder by name folder
Base Command
delinea-folder-search
Input
| Argument Name | Description | Required |
|---|---|---|
| foldername | Search name folder | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Folder.Id | String | Retrieved folder ID from search query |
Command Example
!delinea-folder-search foldername="xsoarFolderTest"
Context Example
{
"Delinea": {
"Folder": {
"Id": [
5
]
}
}
}
Command Example
!delinea-folder-delete folder_id="18"
Context Example
{
"Delinea": {
"Folder": {
"Delete": {
"id": 18,
"objectType": "Folder",
"responseCodes": []
}
}
}
}
delinea-secret-get
Get secret object by ID secret
Base Command
delinea-secret-get
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | ID for secret | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret | String | Secret object |
Command Example
!delinea-secret-get secret_id=2
Context Example
{
"Delinea": {
"Secret": {
"accessRequestWorkflowMapId": -1,
"active": true,
"allowOwnersUnrestrictedSshCommands": false,
"autoChangeEnabled": false,
"autoChangeNextPassword": "2$C$7vl8*SN@",
"checkOutChangePasswordEnabled": false,
"checkOutEnabled": true,
"checkOutIntervalMinutes": -1,
"checkOutMinutesRemaining": 30,
"checkOutUserDisplayName": "XSOAR integration",
"checkOutUserId": 3,
"checkedOut": true,
"doubleLockId": -1,
"enableInheritPermissions": true,
"enableInheritSecretPolicy": true,
"failedPasswordChangeAttempts": 0,
"folderId": 3,
"id": 2,
"isDoubleLock": false,
"isOutOfSync": false,
"isRestricted": true,
"items": [
{
"fieldDescription": "The Server or Location of the Windows Machine.",
"fieldId": 83,
"fieldName": "Machine",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": false,
"isPassword": false,
"itemId": 5,
"itemValue": "192.168.100.1",
"slug": "machine"
},
{
"fieldDescription": "The Username of the Windows User.",
"fieldId": 86,
"fieldName": "Username",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": false,
"isPassword": false,
"itemId": 6,
"itemValue": "w2\\w2",
"slug": "username"
},
{
"fieldDescription": "The password of the Windows User.",
"fieldId": 85,
"fieldName": "Password",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": false,
"isPassword": true,
"itemId": 7,
"itemValue": "1234567890",
"slug": "password"
},
{
"fieldDescription": "Any additional notes.",
"fieldId": 84,
"fieldName": "Notes",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": true,
"isPassword": false,
"itemId": 8,
"itemValue": "",
"slug": "notes"
}
],
"lastHeartBeatCheck": "0001-01-01T00:00:00",
"lastHeartBeatStatus": "Pending",
"lastPasswordChangeAttempt": "0001-01-01T00:00:00",
"launcherConnectAsSecretId": -1,
"name": "test-w2",
"outOfSyncReason": "",
"passwordTypeWebScriptId": -1,
"proxyEnabled": false,
"requiresApprovalForAccess": false,
"requiresComment": false,
"responseCodes": [],
"restrictSshCommands": false,
"secretPolicyId": -1,
"secretTemplateId": 6003,
"secretTemplateName": "Windows Account",
"sessionRecordingEnabled": false,
"siteId": 1
}
}
}
delinea-secret-search
Search secret ID by multiply params
Base Command
delinea-secret-search
Input
| Argument Name | Description | Required |
|---|---|---|
| filter.allowDoubleLocks | Whether to allow DoubleLocks as part of the search. True by default | Optional |
| filter.doNotCalculateTotal | Whether to return the total number of secrets matching the filters. False by default | Optional |
| filter.doubleLockId | Only include Secrets with this DoubleLock ID assigned in the search results | Optional |
| filter.extendedFields | Names of Secret Template fields to return. Only exposed fields can be returned. | Optional |
| filter.extendedTypeId | Return only secrets matching a certain extended type | Optional |
| filter.folderId | Return only secrets within a certain folder | Optional |
| filter.heartbeatStatus | Return only secrets with a certain heartbeat status | Optional |
| filter.includeActive | Whether to include active secrets in results (when excluded equals true) | Optional |
| filter.includeInactive | Whether to include inactive secrets in results | Optional |
| filter.includeRestricted | Whether to include restricted secrets in results | Optional |
| filter.isExactMatch | Whether to do an exact match of the search text or a partial match | Optional |
| filter.onlyRPCEnabled | Whether to only include secrets whose template has Remote Password Changing enabled | Optional |
| filter.onlySharedWithMe | When true only Secrets where you are not the owner and the Secret was shared explicitly with your user id will be returned. | Optional |
| filter.passwordTypeIds | Return only secrets matching certain password types | Optional |
| filter.permissionRequired | Specify whether to filter by List, View, Edit, or Owner permission. Default is List. (List = 1, View = 2, Edit = 3, Owner = 4 | Optional |
| filter.scope | Specify whether to search AllSecrets, Recent, or Favorites (All = 1, Recent = 2,Favorites = 3 | Optional |
| filter.searchField | Field to search | Optional |
| filter.searchFieldSlug | Field-slug to search. This will override SearchField. | Optional |
| filter.searchText | Search text | Optional |
| filter.secretTemplateId | Return only secrets matching a certain template | Optional |
| filter.siteId | Return only secrets within a certain site | Optional |
| skip | Number of records to skip before taking results | Optional |
| sortBy[0].direction | Sort direction | Optional |
| sortBy[0].name | Sort field name | Optional |
| sortBy[0].priority | Priority index. Sorts with lower values are executed earlier | Optional |
| take | Maximum number of records to include in results | Optional |
| filter.includeSubFolders | Whether to include secrets in subfolders of the specified folder | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Secret | String | Search secret object |
Command Example
!delinea-secret-search filter_searchfields="username" filter_searchtext="xsoar"
Context Example
{
"Delinea": {
"Secret": {
"Secret": [
5
]
}
}
}
delinea-folder-update
Update a single secret folder by ID
Base Command
delinea-folder-update
Input
| Argument Name | Description | Required |
|---|---|---|
| folderName | Folder name | Optional |
| folderTypeId | Folder type ID | Optional |
| id | Folder ID. Must match ID in path | Required |
| inheritPermissions | Whether the folder inherits permissions from its parent | Optional |
| inheritSecretPolicy | Whether the folder inherits the secret policy | Optional |
| parentFolderId | ID parent folder | Optional |
| secretPolicyId | Secret Policy ID | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Folder.Update | String | Retrieved return operation update folder |
Command Example
!delinea-folder-update id=4 foldername="SafexsoarTest"
Context Example
{
"Delinea": {
"Folder": {
"Update": {
"childFolders": null,
"folderName": "SafexsoarTest",
"folderPath": "\\Personal Folders\\XSOAR integration\\SafexsoarTest",
"folderTypeId": 1,
"id": 4,
"inheritPermissions": false,
"inheritSecretPolicy": false,
"parentFolderId": 3,
"secretPolicyId": -1,
"secretTemplates": null
}
}
}
}
delinea-secret-create
Create new object Secret
Base Command
delinea-secret-create
Input
| Argument Name | Description | Required |
|---|---|---|
| autoChangeEnabled | AutoChangeEnabled options | Optional |
| checkOutChangePasswordEnabled | CheckOutChangePasswordEnabled options | Optional |
| checkOutEnabled | Whether secret checkout is enabled | Optional |
| checkOutIntervalMinutes | Checkout interval, in minutes (integer) | Optional |
| enableInheritPermissions | Whether the secret inherits permissions from the containing folder | Optional |
| enableInheritSecretPolicy | Whether the secret policy is inherited from the containing folder | Optional |
| folderId | Secret folder ID. May be null unless secrets are required to be in folders.(integer) | Optional |
| launcherConnectAsSecretId | LauncherConnectAsSecretId(integer) | Optional |
| name | Secret name | Required |
| passwordTypeWebScriptId | passwordTypeWebScriptId options(integer) | Optional |
| proxyEnabled | proxyEnabled options | Optional |
| requiresCommen | requiresCommen options | Optional |
| secretPolicyId | secretPolicyId options(integer) | Optional |
| secretTemplateId | Secret Template ID (integer) | Required |
| sessionRecordingEnabled | sessionRecordingEnabled options | Optional |
| siteId | siteId options (integer) | Required |
| sshKeyArgs | sshKeyArgs options(list args) | Optional |
| domain_item | Item Domain for secret. If need to select template. | Optional |
| machine_item | Item Machine for secret. If need to select template. | Optional |
| username_item | Item Username for secret.If need to select template. | Optional |
| password_item | Item Password for secret.If need to select template. | Optional |
| notes_item | Item Notes for secret.IF need to select template. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Create | String | Secret Model |
Command Example
!delinea-secret-create name="xsoarSecret" secrettemplateid="6003" siteid="1" checkoutenabled=true folderid=3 machine_item="my-machine" username_item="my-username" password_item="XXXXXX@@@@@####"
Context Example
{
"Delinea": {
"Secret": {
"Create": {
"accessRequestWorkflowMapId": -1,
"active": true,
"allowOwnersUnrestrictedSshCommands": false,
"autoChangeEnabled": false,
"autoChangeNextPassword": null,
"checkOutChangePasswordEnabled": false,
"checkOutEnabled": true,
"checkOutIntervalMinutes": -1,
"checkOutMinutesRemaining": 0,
"checkOutUserDisplayName": "",
"checkOutUserId": 0,
"checkedOut": false,
"doubleLockId": 0,
"enableInheritPermissions": true,
"enableInheritSecretPolicy": false,
"failedPasswordChangeAttempts": 0,
"folderId": 3,
"id": 5,
"isDoubleLock": false,
"isOutOfSync": false,
"isRestricted": true,
"items": [
{
"fieldDescription": "The Server or Location of the Windows Machine.",
"fieldId": 83,
"fieldName": "Machine",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": false,
"isPassword": false,
"itemId": 19,
"itemValue": "my-machine",
"slug": "machine"
},
{
"fieldDescription": "The Username of the Windows User.",
"fieldId": 86,
"fieldName": "Username",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": false,
"isPassword": false,
"itemId": 20,
"itemValue": "my-username",
"slug": "username"
},
{
"fieldDescription": "The password of the Windows User.",
"fieldId": 85,
"fieldName": "Password",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": false,
"isPassword": true,
"itemId": 21,
"itemValue": "XXXXXX@@@@@####",
"slug": "password"
},
{
"fieldDescription": "Any additional notes.",
"fieldId": 84,
"fieldName": "Notes",
"fileAttachmentId": null,
"filename": null,
"isFile": false,
"isNotes": true,
"isPassword": false,
"itemId": 22,
"itemValue": "",
"slug": "notes"
}
],
"lastHeartBeatCheck": "0001-01-01T00:00:00",
"lastHeartBeatStatus": "Pending",
"lastPasswordChangeAttempt": "0001-01-01T00:00:00",
"launcherConnectAsSecretId": -1,
"name": "xsoarSecret",
"outOfSyncReason": "",
"passwordTypeWebScriptId": -1,
"proxyEnabled": false,
"requiresApprovalForAccess": false,
"requiresComment": false,
"responseCodes": [],
"restrictSshCommands": false,
"secretPolicyId": -1,
"secretTemplateId": 6003,
"secretTemplateName": "Windows Account",
"sessionRecordingEnabled": false,
"siteId": 1
}
}
}
}
delinea-secret-delete
Delete secret
Base Command
delinea-secret-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| id | ID secret for delete | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Delete | String | Information about an object that was deleted |
Command Example
!delinea-secret-delete id=2
Context Example
{
"Delinea": {
"Secret": {
"Deleted": {
"id": 2,
"objectType": "Secret",
"responseCodes": []
}
}
}
}
delinea-secret-server-user-create
Create a new Secret Server user
Base Command
delinea-secret-server-user-create
Input
| Argument Name | Description | Required |
|---|---|---|
| displayName | User display name | Required |
| password | Password for new user | Required |
| userName | Username | Required |
| adGuid | Active Directory unique identifier | Optional |
| domainId | Active Directory domain ID | Optional |
| duoTwoFactor | Whether Duo two-factor authentication is enabled | Optional |
| emailAddress | User email address | Optional |
| enabled | Whether the user account is enabled | Optional |
| fido2TwoFactor | Whether Duo two-factor authentication is enabled | Optional |
| isApplicationAccount | IsApplicationAccount | Optional |
| oathTwoFactor | Whether OATH two-factor authentication is enabled | Optional |
| radiusTwoFactor | Whether RADIUS two-factor authentication is enabled | Optional |
| radiusUserName | RADIUS username | Optional |
| twoFactor | Whether two-factor authentication is enabled | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Server.User.Create | String | User Model |
Command Example
!delinea-secret-server-user-create displayname="UserOne" password="12345" username="UserOne"
Context Example
{
"Delinea": {
"User": {
"Create": {
"adAccountExpires":"0001-01-01T00:00:00",
"adGuid":null,
"created":"2022-06-01T08:31:15.275Z",
"dateOptionId":-1,
"displayName":"UserOne",
"domainId":-1,
"duoTwoFactor":false,
"emailAddress":null,
"enabled":true,
"externalUserSource":"None",
"fido2TwoFactor":false,
"id":29,
"ipAddressRestrictions":null,
"isApplicationAccount":false,
"isEmailCopiedFromAD":false,
"isEmailVerified":false,
"isLockedOut":false,
"lastLogin":0001-01-01T00:00:00,
"lastSessionActivity":null,
"lockOutReason":null,
"lockOutReasonDescription":null,
"loginFailures":0,
"mustVerifyEmail":false,
"oathTwoFactor":false,
"oathVerified":false,
"passwordLastChanged":"0001-01-01T00:00:00",
"personalGroupId":0,
"radiusTwoFactor":false,
"radiusUserName":null,
"resetSessionStarted":"0001-01-01T00:00:00",
"slackId":null,
"timeOptionId":-1,
"twoFactor":false,
"unixAuthenticationMethod":Password,
"userLcid":0,
"userName":"UserOne",
"verifyEmailSentDate":"0001-01-01T00:00:00"
}
}
}
}
delinea-secret-server-user-search
Search, filter, sort, and page Secret Server users
Base Command
delinea-secret-server-user-search
Input
| Argument Name | Description | Required |
|---|---|---|
| filter.domainId | Filter users by Active Directory domain (integer) | Optional |
| filter.includeInactive | Whether to include inactive users in the results | Optional |
| filter.searchFields | Fields to search | Optional |
| filter.searchText | Search text | Optional |
| skip | Number of records to skip before taking results | Optional |
| sortBy[0].direction | Sort direction | Optional |
| sortBy[0].name | Sort field name | Optional |
| sortBy[0].priority | Priority index. Sorts with lower values are executed earlier (integer) | Optional |
| take | Maximum number of records to include in results(integer) | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Server.User.Search | String | Specify paging and sorting options for querying records and returning results |
Command Example
!delinea-secret-server-user-search filter_searchfields="userName" filter_searchtext="xsoarUser"
Context Example
{
"Delinea": {
"User": {
"Search": null
}
}
}
delinea-secret-server-user-update
Update a single Secret Server user by ID
Base Command
delinea-secret-server-user-update
Input
| Argument Name | Description | Required |
|---|---|---|
| id | User ID | Required |
| dateOptionId | DateOptionId(integer) | Optional |
| displayName | Display name | Optional |
| duoTwoFactor | Whether Duo two-factor authentication is enabled | Optional |
| emailAddress | Optional | |
| enabled | Whether the user account is enabled | Optional |
| fido2TwoFactor | Whether FIDO2 two-factor authentication is enabled | Optional |
| groupOwners | GroupOwners(integer) | Optional |
| isApplicationAccount | IsApplicationAccount | Optional |
| isGroupOwnerUpdate | isGroupOwnerUpdate | Optional |
| isLockedOut | Whether the user is locked out | Optional |
| loginFailures | Number of login failures | Optional |
| oathTwoFactor | Whether OATH two-factor authentication is enabled | Optional |
| password | Password | Optional |
| radiusTwoFactor | Whether RADIUS two-factor authentication is enabled | Optional |
| radiusUserName | RADIUS username | Optional |
| timeOptionId | timeOptionId (integer) | Optional |
| twoFactor | Whether two-factor authentication is enabled | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Server.User.Update | String | User Model |
Command Example
!delinea-secret-server-user-update id=28 displayname="myTestUser"
Context Example
{
"Delinea": {
"User": {
"Update": {
"unixAuthenticationMethod":"Password",
"enabled":true,
"passwordLastChanged":"0001-01-01T00:00:00",
"isEmailCopiedFromAD":false,
"isApplicationAccount":false,
"lockOutReason":null,
"created":"2022-06-01T08:09:39",
"radiusUserName":"UserOne",
"radiusTwoFactor":false,
"verifyEmailSentDate":"0001-01-01T00:00:00",
"adAccountExpires":"0001-01-01T00:00:00",
"slackId":null,
"adGuid":null,
"displayName":"myTestUser",
"oathVerified":false,
"lastSessionActivity":null,
"externalUserSource":"None",
"loginFailures":0,
"lastLogin":"0001-01-01T00:00:00",
"ipAddressRestrictions":null,
"oathTwoFactor":false,
"lockOutReasonDescription":null,
"userName":"UserOne",
"fido2TwoFactor":false,
"emailAddress":null,
"resetSessionStarted":"0001-01-01T00:00:00",
"mustVerifyEmail":false,
"isEmailVerified":false,
"personalGroupId":0,
"isLockedOut":false,
"id":28,
"twoFactor":false,
"duoTwoFactor":false,
"timeOptionId":-1,
"userLcid":0,
"dateOptionId":-1,
"domainId":-1
}
}
}
}
delinea-secret-server-user-delete
Delete a Secret Server user by ID
Base Command
delinea-secret-server-user-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| id | User ID | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Server.User.Delete | String | Information about an object that was deleted |
Command Example
!delinea-secret-server-user-delete id=5
Context Example
{
"Delinea": {
"User": {
"Delete": {
"id": 5,
"objectType": "User",
"responseCodes": null
}
}
}
}
delinea-secret-server-user-get
Get Secret Server users list
Base Command
delinea-secret-server-user-get
Input
This command has no input arguments.
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.Server.User | String | User object |
Command Example
#### Context Example
```json
{
"Delinea": {
"Secret": {
"Server": {
"User": [
{
"id": 1,
"userName": "admin",
"displayName": "Administrator",
"enabled": true
}
]
}
}
}
}
delinea-secret-rpc-changepassword
Change a secret’s password
Base Command
delinea-secret-rpc-changepassword
Input
| Argument Name | Description | Required |
|---|---|---|
| secret_id | Secret ID | Required |
| newPassword | New secret password | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Secret.ChangePassword | String | Secret summary object |
Command Example
!delinea-secret-rpc-changepassword secret_id=4 newPassword="Test000"
Context Example
{
"Delinea": {
"Secret": {
"ChangePassword": {
"active": true,
"autoChangeEnabled": false,
"checkOutEnabled": false,
"checkedOut": false,
"createDate": "2020-11-02T18:06:07.357",
"daysUntilExpiration": null,
"doubleLockEnabled": false,
"extendedFields": null,
"folderId": -1,
"hidePassword": false,
"id": 4,
"inheritsPermissions": false,
"isOutOfSync": false,
"isRestricted": false,
"lastAccessed": null,
"lastHeartBeatStatus": "Success",
"lastPasswordChangeAttempt": "0001-01-01T00:00:00",
"name": "g1-machine",
"outOfSyncReason": "",
"requiresApproval": false,
"requiresComment": false,
"responseCodes": null,
"secretTemplateId": 6007,
"secretTemplateName": "Unix Account (SSH)",
"siteId": 1
}
}
}
}
delinea-fetch-users
Fetch credentials from secret
Base Command
delinea-fetch-users
Input
NO input argumets
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.User.Credentials | String | Secret credential objects |
Command Example
#### Context Example
```json
[
{
"name": "4219",
"password": "test3",
"user": "test3"
},
{
"name": "4217",
"password": "dhPQhf1d@!E",
"user": "secret2"
}
]
delinea-platform-user-create
Create a new user in Platform
Base Command
delinea-platform-user-create
Input
| Argument Name | Description | Required |
|---|---|---|
| MobileNumber | The user mobile number. | Optional |
| ID | The UUID of the cloud user to change. | Optional |
| InEverybodyRole | The user is in the Everybody role? | Optional |
| CmaRedirectedUserUuid | The MFA redirected user UUID. | Optional |
| OfficeNumber | The user office number. | Optional |
| ReportsTo | The user reports to this user UUID. | Optional |
| PreferredCulture | The user preferred culture. | Optional |
| DisplayName | The user display. | Optional |
| Password | Password for new user. The password used to log in. | Required |
| Name | The user name. | Required |
| AccountExp | Account expires date/time. | Optional |
| PasswordNeverExpire | Does user’s password expire? | Optional |
| The User email. | Optional | |
| ServiceUser | Whether this is a service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license. | Optional |
| Description | The User description. | Optional |
| HomeNumber | The user home number. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Platform.User.Create | String | Result |
Command Example
!delinea-platform-user-create Password="Test@123" Name="uniquexsoar1" ServiceUser="true"
Context Example
{
"Delinea": {
"Platform" : {
"User": {
"Create": {
"Result": "a09eb441-f0a0-4894-a129-af4e0b3559d6",
"success": true,
"Message": null,
"MessageID": null,
"Exception": null,
"ErrorID": null,
"ErrorCode": null,
"IsSoftError": false,
"InnerExceptions": null
}
}
}
}
}
delinea-platform-user-get
Get single Platform user by uuid
Base Command
delinea-platform-user-get
Input
| Argument Name | Description | Required |
|---|---|---|
| userUuidOrUpn | Fetches a Platform user by uuid or upn | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Platform.User.Get | String | User Model |
Command Example
!delinea-platform-user-get userUuidOrUpn="09b9a9b0-6ce8-465f-ab03-65766d33b05e"
Context Example
{
"Delinea": {
"Platform": {
"User": {
"Get": {
"directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
"directoryServiceName": "Delinea",
"directoryInstanceName": "Delinea",
"uuid": "c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"name": "admin@loud",
"displayName": "admin",
"state": "Active",
"lastLogin": "2025-09-29T13:37:19.4639582Z",
"lastInvite": "2025-04-16T17:38:47.0519372Z",
"platformMembershipType": "Employee",
"_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428440b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37we",
"_links": {
"self": {
"href": "/api/users/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428440b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37we",
"title": "PlatformUser(Platform): admin"
},
"directory-users": [
{
"href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05R/users/c2c7bcc6-9560-44e0-8dff-5be221cd37e",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37we",
"title": "User(Delinea): admin"
}
]
}
}
}
}
}
}
delinea-platform-user-update
Update a single Platform user by ID
Base Command
delinea-platform-user-update
Input
| Argument Name | Description | Required |
|---|---|---|
| MobileNumber | The user mobile number. | Optional |
| ID | The UUID of the cloud user to change. | Required |
| InEverybodyRole | The user is in the Everybody role? | Optional |
| CmaRedirectedUserUuid | The MFA redirected user uuid. | Optional |
| OfficeNumber | The user office number. | Optional |
| ReportsTo | The user reports to this user UUID. | Optional |
| PreferredCulture | The user preferred culture. | Optional |
| DisplayName | The user display. | Optional |
| Password | Password for new user. The password used to log in. | Optional |
| Name | The user name. | Optional |
| AccountExp | Account expires date/time. | Optional |
| PasswordNeverExpire | Does user’s password expire? | Optional |
| The User email. | Optional | |
| ServiceUser | Whether this is a service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license. | Optional |
| Description | The User description. | Optional |
| HomeNumber | The user home number. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Platform.User.Update | String | User is successfully updated then returning success: true in result |
Command Example
!delinea-platform-user-update ID="b02319fc-b26a-4352-8e4e-d8ea1188f160" Name="xsoarUserTest1"
Context Example
{
"Delinea": {
"Platform": {
"User": {
"Update": {
"success": true,
"Result": null,
"Message": null,
"MessageID": null,
"Exception": null,
"ErrorID": null,
"ErrorCode": null,
"IsSoftError": false,
"InnerExceptions": null
}
}
}
}
}
delinea-platform-user-delete
Delete a Platform user by UUID or Name
Base Command
delinea-platform-user-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| id | User UUID | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Platform.User.Delete | String | Information about an object that was deleted and returning success: true in result |
Command Example
!delinea-platform-user-delete id="a09eb441-f0a0-4894-a129-af4e0b3559d6"
Context Example
{
"Delinea": {
"Platform": {
"User": {
"Delete": {
"success": true,
"Result": null,
"Message": null,
"MessageID": null,
"Exception": null,
"ErrorID": null,
"ErrorCode": null,
"IsSoftError": false,
"InnerExceptions": null
}
}
}
}
}
delinea-platform-get-all-users
Get single Platform user by uuid
Base Command
delinea-platform-get-all-users
Input
| Argument Name | Description | Required |
|---|---|---|
| filter_displayName | Display name to filter users. | Optional |
| pageSize | Page size. Default 1000. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Platform.Users | String | Returning users based on pageSize and default page size is 1000 |
Command Example
!delinea-platform-get-all-users pageSize="1"
Context Example
{
"Delinea": {
"Platform": {
"Get" : {
"All" : {
"Users": {
"users": [
{
"directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
"directoryServiceName": "Delinea",
"directoryInstanceName": "Delinea",
"uuid": "c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"name": "cloudadmin@cloud",
"displayName": "cloudadmin",
"state": "Active",
"lastLogin": "2025-09-29T13:37:19.4639582Z",
"lastInvite": "2025-04-16T17:38:47.0519372Z",
"platformMembershipType": "Employee",
"_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"_links": {
"self": {
"href": "/api/users/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"title": "PlatformUser(Platform): cloudadmin"
},
"directory-users": [
{
"href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05E/users/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/c2c7bcc6-9560-44e0-8dff-5be221cd37ee",
"title": "User(Delinea): cloudadmin"
}
]
}
}
]
}
}
}
}
}
}
delinea-platform-get-user-search-by-text
Get Platform users search by Text
Base Command
delinea-platform-get-user-search-by-text
Input
| Argument Name | Description | Required |
|---|---|---|
| filter.searchText | Search Text is looked for in multiple fields | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Delinea.Platform.UserSearchResults | String | SearchText is looked for in multiple fields and returning results |
Command Example
!delinea-platform-get-user-search-by-text filter.searchText="sail"
Context Example
{
"Delinea": {
"Platform": {
"Get" : {
"User" : {
"Searchbytext": {
"users": [
{
"directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
"directoryServiceName": "Delinea",
"directoryInstanceName": "Delinea",
"uuid": "3f4b80c0-c853-473f-9534-66e4a8331843",
"name": "ren@cloud",
"displayName": "sailpoint+user.service",
"state": "Created",
"platformMembershipType": "Employee",
"_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/3f4b80c0-c853-473f-9534-66e4a8331843",
"_links": {
"self": {
"href": "/api/users/3f4b80c0-c853-473f-9534-66e4a8331843",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/3f4b80c0-c853-473f-9534-66e4a8331843",
"title": "PlatformUser(Platform): sailpoint+user.service"
},
"directory-users": [
{
"href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05E/users/3f4b80c0-c853-473f-9534-66e4a8331843",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/3f4b80c0-c853-473f-9534-66e4a8331843",
"title": "User(Delinea): sailpoint+user.service"
}
]
}
},
{
"directoryServiceUuid": "09b9a9b0-6ce8-465f-ab03-65766d33b05e",
"directoryServiceName": "Delinea",
"directoryInstanceName": "Delinea",
"uuid": "b977dd7d-b771-40b6-83f3-f04154a733c5",
"name": "roderick@cloud",
"displayName": "roderick",
"state": "Active",
"lastLogin": "2025-08-28T17:52:02.0344759Z",
"platformMembershipType": "Employee",
"_drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/b977dd7d-b771-40b6-83f3-f04154a733c5",
"_links": {
"self": {
"href": "/api/users/b977dd7d-b771-40b6-83f3-f04154a733c5",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:platformuser/platform/09b9a9b0-6ce8-465f-ab03-65766d33b05e/b977dd7d-b771-40b6-83f3-f04154a733c5",
"title": "PlatformUser(Platform): roderick"
},
"directory-users": [
{
"href": "/api/directory-services/09B9A9B0-6CE8-465F-AB03-65766D33B05E/users/b977dd7d-b771-40b6-83f3-f04154a733c5",
"method": "GET",
"drn": "drn:dws:76a86745-ca2c-4ff2-ac98-463428343b8a:identity:user/delinea/09b9a9b0-6ce8-465f-ab03-65766d33b05e/b977dd7d-b771-40b6-83f3-f04154a733c5",
"title": "User(Delinea): roderick"
}
]
}
}
]
}
}
}
}
}
}
Configuration parameters
url— Server URL (e.g. https://example.net) (required)credentials— Username (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsisFetchCredentials— Fetches Credentialssecrets— Secret IDs (Provide multiple Id's by using ',' example- 1,2,3)
Commands (26)
-
delinea-folder-createCreate a new folder.
-
delinea-folder-deleteDelete a folder by folder ID.
-
delinea-folder-searchSearch a specific folder by name.
-
delinea-folder-updateUpdate a single secret folder by ID.
-
delinea-platform-get-all-usersFetch all users from the platform.
-
delinea-platform-get-user-search-by-textList of platform users matching search text.
-
delinea-platform-user-createCreate a new user in Platform.
-
delinea-platform-user-deleteDelete Platform user by ID.
-
delinea-platform-user-getFetch a Platform user by uuid or upn.
-
delinea-platform-user-updateUpdate a Platform user by ID.
-
delinea-secret-checkinCheck in a secret.
-
delinea-secret-checkoutCheck out a secret.
-
delinea-secret-createCreate a new secret.
-
delinea-secret-deleteDelete secret by id.
-
delinea-secret-getGet secret object by secret ID.
-
delinea-secret-password-getExtracting the password field from the required secret.
-
delinea-secret-password-updateUpdate password for a secret by ID.
-
delinea-secret-rpc-changepasswordRemote password changing.
-
delinea-secret-searchSearch secret by multiply parameters.
-
delinea-secret-search-nameSearch for a secret using secret name.
-
delinea-secret-server-user-createCreate a new user in Secret Server.
-
delinea-secret-server-user-deleteDelete Secret Server user by ID.
-
delinea-secret-server-user-getGet Secret Server users list.
-
delinea-secret-server-user-searchUser search, filter and sort in Secret Server.
-
delinea-secret-server-user-updateUpdate a single user by ID in Secret Server.
-
delinea-secret-username-getExtracting the username field from the required secret.
category: Authentication & Identity Management provider: Delinea sectionorder: - Connect commonfields: id: DelineaSS version: -1 configuration: - display: Server URL (e.g. https://example.net) name: url required: true type: 0 section: Connect - display: Username name: credentials required: true type: 9 section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Fetches Credentials name: isFetchCredentials type: 8 required: false section: Connect - display: Secret IDs (Provide multiple Id's by using ',' example- 1,2,3) name: secrets type: 12 required: false section: Connect description: Delinea Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution. display: DelineaSS name: DelineaSS script: commands: - arguments: - description: Secret ID. name: secret_id required: true - description: Notes to get the password. name: autoComment description: Extracting the password field from the required secret. name: delinea-secret-password-get outputs: - contextPath: Delinea.Secret.Password description: Password from secret. type: String - arguments: - description: Secret ID. name: secret_id required: true description: Extracting the username field from the required secret. name: delinea-secret-username-get outputs: - contextPath: Delinea.Secret.Username description: Username from secret. type: String - arguments: - description: Search for secret using secret name. name: search_name required: true description: Search for a secret using secret name. name: delinea-secret-search-name outputs: - contextPath: Delinea.Secret.Id description: List of Secret IDs. type: String - arguments: - description: Secret ID. name: secret_id required: true - description: New password value. name: newpassword required: true secret: true - description: Notes to update the password. name: autoComment description: Update password for a secret by ID. name: delinea-secret-password-update outputs: - contextPath: Delinea.Secret.Newpassword description: New password changed for secret. type: String - arguments: - description: Secret ID. name: secret_id required: true description: Check out a secret. name: delinea-secret-checkout outputs: - contextPath: Delinea.Secret.Checkout description: Returns response (None = Successful). type: String - arguments: - description: Secret ID. name: secret_id required: true description: Check in a secret. name: delinea-secret-checkin outputs: - contextPath: Delinea.Secret.Checkin description: Secret object. type: String - arguments: - description: Name for new folder. name: foldername required: true - defaultValue: '1' description: Folder type ID, 1 - for folder. name: foldertypeid predefined: - '' required: true - description: Parent folder ID. name: parentfolderid required: true - auto: PREDEFINED description: 'Whether the folder should inherit permissions from its parent (default: true).' name: inheritpermissions predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the folder should inherit the secret policy. Defaults to true unless creating a root folder. name: inheritsecretpolicy predefined: - 'true' - 'false' - description: Secret policy ID. name: secretpolicyid description: Create a new folder. name: delinea-folder-create outputs: - contextPath: Delinea.Folder.Create description: New object folder. type: String - arguments: - description: Search folder name. name: foldername required: true description: Search a specific folder by name. name: delinea-folder-search outputs: - contextPath: Delinea.Folder.Id description: List of Folder IDs. type: String - arguments: - description: Folder ID. name: folder_id required: true description: Delete a folder by folder ID. name: delinea-folder-delete outputs: - contextPath: Delinea.Folder.Delete description: Folder ID. type: String - arguments: - description: Secret ID. name: secret_id required: true - description: Notes to get a secret. name: autoComment description: Get secret object by secret ID. name: delinea-secret-get outputs: - contextPath: Delinea.Secret description: Secret object. type: String - arguments: - auto: PREDEFINED description: Whether to allow DoubleLocks as part of the search. True by default. name: filter_allowdoublelocks predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether to return the total number of secrets matching the filters. False by default. name: filter_donotcalculatetotal predefined: - 'true' - 'false' - description: Only include Secrets with this DoubleLock ID assigned in the search results. name: filter_doublelockid - description: Names of Secret Template fields to return. Only exposed fields can be returned. name: filter_extendedfields - description: Return only secrets matching a certain extended type. name: filter_extendedtypeid - description: Return only secrets within a certain folder. name: filter_folderid - description: Return only secrets with a certain heartbeat status. name: filter_heartbeatstatus - auto: PREDEFINED description: Whether to include active secrets in results (when excluded equals true). name: filter_includeactive predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether to include inactive secrets in results. name: filter_includeinactive predefined: - 'true' - 'false' - auto: PREDEFINED description: "Whether to include restricted secrets in results." name: filter_includerestricted predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether to do an exact match of the search text or a partial match. name: filter_isexactmatch predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether to only include secrets whose template has Remote Password Changing enabled. name: filter_onlyrpcenabled predefined: - 'true' - 'false' - auto: PREDEFINED description: When true only Secrets where you are not the owner and the Secret was shared explicitly with your user id will be returned. name: filter_onlysharedwithme predefined: - 'true' - 'false' - description: Return only secrets matching certain password types. name: filter_passwordtypelds - auto: PREDEFINED description: Specify whether to filter by List, View, Edit, or Owner permission. Default is List. (List = 1, View = 2, Edit = 3, Owner = 4). name: filter_permissionrequired predefined: - '1' - '2' - '3' - '4' - auto: PREDEFINED description: Specify whether to search AllSecrets, Recent, or Favorites (All = 1, Recent = 2, Favorites = 3). name: filter_scope predefined: - '1' - '2' - '3' - description: Field to search. name: filter_searchfield - description: Field-slug to search. This will override SearchField. name: filter_searchfieldslug - description: Search text. name: filter_searchtext - description: Return only secrets matching a certain template. name: filter_secrettemplateid - description: Return only secrets within a certain site. name: filter_siteid - description: Number of records to skip before taking results. name: skip - description: Sort direction. name: sortBy_direction - description: Sort field name. name: sortBy_name - description: Priority index. Sorts with lower values are executed earlier. name: sortBy_priority - description: Maximum number of records to include in results. name: take - auto: PREDEFINED description: Whether to include secrets in subfolders of the specified folder. name: filter_includesubfolders predefined: - 'true' - 'false' description: Search secret by multiply parameters. name: delinea-secret-search outputs: - contextPath: Delinea.Secret.Secret description: List of Folder IDs. type: String - arguments: - description: Folder name. name: foldername - description: Folder type ID. name: foldertypeid - description: Folder ID. Must match ID in path. name: id required: true - auto: PREDEFINED description: Whether the folder inherits permissions from its parent. name: inheritpermissions predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the folder inherits the secret policy. name: inheritsecretpolicy predefined: - 'true' - 'false' - description: ID parent folder. name: parentfolderid - description: Secret Policy ID. name: secretpolicyid description: Update a single secret folder by ID. name: delinea-folder-update outputs: - contextPath: Delinea.Folder.Update description: Folder object. type: String - arguments: - auto: PREDEFINED description: Whether the secret’s password is automatically rotated on a schedule. name: autochangeenabled predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the secret’s password is automatically changed when a secret is checked in. This is a security feature that prevents a use of the password retrieved from check-out after the secret is checked in. name: checkoutchangepasswordenabled predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the user must check-out the secret to view it. Checking out gives the user exclusive access to the secret for a specified period or until the secret is checked in. name: checkoutenabled predefined: - 'true' - 'false' - description: The number of minutes that a secret will remain checked out. name: checkoutintervalminutes - auto: PREDEFINED description: Whether the secret inherits permissions from the containing folder. name: enableinheritpermissions predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the secret policy is inherited from the containing folder. name: enableinheritsecretpolicy predefined: - 'true' - 'false' - description: Secret folder ID. If the secret is contained in a folder, the id of the containing folder. Use -1 for secrets that are in the root folder. name: folderid - description: When an SSH secret is proxied, you can choose to connect as another user and then do an su to the current secret’s user. This is a common practice for connecting with a lower privileged account and then switching to the root user. name: launcherconnectassecretid - description: Secret name. name: name required: true - description: The id of the password change script to use on applicable web password secrets. name: passwordtypewebscriptld - auto: PREDEFINED description: Whether the user must enter a comment to view the secret. name: requirescommen predefined: - 'true' - 'false' - description: The id of the secret policy that controls the security and other settings of the secret. name: secretpolicyid - description: Secret Template ID (integer). name: secrettemplateid required: true - auto: PREDEFINED description: Whether session recording is enabled. name: sessionrecordingenabled predefined: - 'true' - 'false' - defaultValue: '1' description: The id of the distributed engine site that is used by this secret for operations such as password changing. name: siteid - description: |- sshKeyArgs options. generateSshKeys (bool) – Whether to generate an SSH private key. generatePassphrase (bool) – Whether to generate an SSH private key passphrase. Only applicable when the Secret template has a password changer with the Private Key Passphrase field mapped. If it is not mapped, this setting is ignored. name: sshkeyargs - description: Item Domain for secret. If need to select template. name: domain_item - description: Item Machine for secret. If need to select template. name: machine_item - description: Item Username for secret. If need to select template. name: username_item - description: Item Password for secret. If need to select template. name: password_item - description: Item Notes for secret. If need to select template. name: notes_item - auto: PREDEFINED description: Whether the secret should be flagged for immediate password change. name: autochangenextpassword predefined: - 'true' - 'false' - description: The id of the mapping entity that associates this secret to a specific access request workflow. name: accessRequestWorkflowMapId description: Create a new secret. name: delinea-secret-create outputs: - contextPath: Delinea.Secret.Create description: Secret object. type: String - arguments: - description: ID secret for delete. name: id required: true - description: Notes to Delete the secret. name: autoComment description: Delete secret by id. name: delinea-secret-delete outputs: - contextPath: Delinea.Secret.Delete description: Secret object. type: String - arguments: - description: The user's name as displayed in the user interface. name: displayname required: true - description: Password for new user. The password used to log in. name: password required: true - description: Username. name: username required: true - description: Active Directory unique identifier. name: adguid - description: Active Directory domain ID. name: domainid - auto: PREDEFINED description: Whether Duo two-factor authentication is enabled. name: duotwofactor predefined: - 'true' - 'false' - description: The user's email address. Used by the system to send reports, access requests, and other notifications. name: emailaddress - auto: PREDEFINED defaultValue: 'true' description: Whether the user account is enabled. Disabled users are unable to log in and do not consume a user license. name: enabled predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether FIDO2 two-factor authentication is enabled. name: fido2twofactor predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether this is an application account. Application accounts are used for automation, cannot log in using the UI, and do not consume a user license. name: isapplicationaccount predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether OATH two-factor authentication is enabled. name: oathtwofactor predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether RADIUS two-factor authentication is enabled. name: radiustwofactor predefined: - 'true' - 'false' - description: When a user account uses RADIUS two-factor authentication, this property is the user name of the RADIUS account used to authenticate this user. name: radiususername - auto: PREDEFINED description: Whether two-factor authentication is enabled. name: twofactor predefined: - 'true' - 'false' description: Create a new user in Secret Server. name: delinea-secret-server-user-create outputs: - contextPath: Delinea.Secret.Server.User.Create description: User object. type: String compliantpolicies: - User Hard Remediation - arguments: - description: Filter users by Active Directory domain (integer). name: filter_domainid - auto: PREDEFINED description: Whether to include inactive users in the results. name: filter_includeinactive predefined: - 'true' - 'false' - description: Fields to search. name: filter_searchfields - description: Search text. name: filter_searchtext - description: Number of records to skip before taking results. name: skip - description: Sort direction. name: sortBy_direction - description: Sort field name. name: sortBy_name - description: Priority index. Sorts with lower values are executed earlier (integer). name: sortBy_priority - description: Maximum number of records to include in results (integer). name: take description: User search, filter and sort in Secret Server. name: delinea-secret-server-user-search outputs: - contextPath: Delinea.Secret.Server.User.Search description: List of User IDs. type: String - arguments: - description: User ID. Must match ID in path. name: id required: true - description: The id of the date format to use when displaying dates to this user. These options are defined in Admin > Configuration. name: dateoptionid - description: The user's name as displayed in the user interface. name: displayname - auto: PREDEFINED description: Whether Duo two-factor authentication is enabled. name: duotwofactor predefined: - 'true' - 'false' - description: The user's email address. Used by the system to send reports, access requests, and other notifications. name: emailaddress - auto: PREDEFINED description: Whether the user account is enabled. Disabled users are unable to log in and do not consume a user license. name: enabled predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether FIDO2 two-factor authentication is enabled. name: fido2twofactor predefined: - 'true' - 'false' - description: A list of group ids for the groups that can manage this user. name: groupowners - auto: PREDEFINED description: Whether this is an application account. Application accounts are used for automation, cannot log in using the UI, and do not consume a user license. name: isapplicationaccount predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the user is managed by the groups specified in GroupOwners or is managed by all users with the 'Administer Users' role permission. name: isgroupownerupdate predefined: - 'true' - 'false' - auto: PREDEFINED description: Whether the user is locked out. name: isLockedout predefined: - 'true' - 'false' - description: Number of login failures to allow before the account is locked out. Set to 0 for unlimited login attempts. name: loginfailures - auto: PREDEFINED description: Whether OATH two-factor authentication is enabled. name: oathtwofactor predefined: - 'true' - 'false' - description: Password for update user. The password used to log in. name: password - auto: PREDEFINED description: Whether RADIUS two-factor authentication is enabled. name: radiustwofactor predefined: - 'true' - 'false' - description: When a user account uses RADIUS two-factor authentication, this property is the user name of the RADIUS account used to authenticate this user. name: radiususername - description: The id of the time format to use when displaying times to this user. These options are defined in Admin > Configuration. name: timeoptionid - auto: PREDEFINED description: Whether two-factor authentication is enabled. name: twofactor predefined: - 'true' - 'false' - auto: PREDEFINED description: Determines the type of Unix authentication to use. Must be Password (0), PublicKey (1), PasswordOrPublicKey (2), or PasswordAndPublicKey (3). name: unixauthenticationmethodtype predefined: - '0' - '1' - '2' - '3' description: Update a single user by ID in Secret Server. name: delinea-secret-server-user-update outputs: - contextPath: Delinea.Secret.Server.User.Update description: User object. type: String compliantpolicies: - EndPoint Isolation - User Hard Remediation - arguments: - description: User ID. name: id required: true description: Delete Secret Server user by ID. name: delinea-secret-server-user-delete outputs: - contextPath: Delinea.Secret.Server.User.Delete description: User object. type: String compliantpolicies: - EndPoint Isolation - User Hard Remediation - arguments: [] description: Get Secret Server users list. execution: false name: delinea-secret-server-user-get outputs: - contextPath: Delinea.Secret.Server.User description: User object. type: String compliantpolicies: - User Hard Remediation - arguments: - description: Secret ID. name: secret_id required: true - description: The new password. name: newpassword required: true - description: Notes to change the password. name: autoComment description: Remote password changing. name: delinea-secret-rpc-changepassword outputs: - contextPath: Delinea.Secret.ChangePassword description: Secret summary. type: String - arguments: - description: Mobile number of the user. name: MobileNumber - description: The UUID of the cloud user to change. name: ID - description: The user is in the Everybody role? name: InEverybodyRole predefined: - 'true' - 'false' - description: The MFA redirected user uuid. name: CmaRedirectedUserUuid - description: The user office number. name: OfficeNumber - description: The user reports to this user UUID. name: ReportsTo - description: The user preferred culture. name: PreferredCulture - description: The user display. name: DisplayName - description: Password for new user. The password used to log in. name: Password required: true - description: The user name. name: Name required: true - description: Account expires date/time. name: AccountExp - description: Does user's password expire? name: PasswordNeverExpire predefined: - 'true' - 'false' - description: The User email. name: Mail - description: Whether this is an service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license. name: ServiceUser predefined: - 'true' - 'false' - description: The User description. name: Description - description: The user home number. name: HomeNumber description: Create a new user in Platform. name: delinea-platform-user-create outputs: - contextPath: Delinea.Platform.User.Create description: User object. type: String - arguments: - description: The name or UUID of the user to remove. name: id required: true description: Delete Platform user by ID. name: delinea-platform-user-delete outputs: - contextPath: Delinea.Platform.User.Delete description: User object. type: String compliantpolicies: - EndPoint Isolation - User Hard Remediation - arguments: - description: Mobile number of the user. name: MobileNumber - description: The UUID of the cloud user to change. name: ID required: true - description: The user is in the Everybody role? name: InEverybodyRole predefined: - 'true' - 'false' - description: The MFA redirected user uuid. name: CmaRedirectedUserUuid - description: The user office number. name: OfficeNumber - description: The user reports to this user UUID. name: ReportsTo - description: The user preferred culture. name: PreferredCulture - description: The user display . name: DisplayName - description: Password for new user. The password used to log in. name: Password - description: The user name. name: Name - description: Account expires date/time. name: AccountExp - description: Does user's password expire? name: PasswordNeverExpire predefined: - 'true' - 'false' - description: The User email. name: Mail - description: Whether this is an service account. Service accounts are used for automation, cannot log in using the UI, and do not consume a user license. name: ServiceUser predefined: - 'true' - 'false' - description: The User description. name: Description - description: The user home number. name: HomeNumber description: Update a Platform user by ID. name: delinea-platform-user-update outputs: - contextPath: Delinea.Platform.User.Update description: User object. type: String - arguments: - description: Fetches a platform user by uuid or upn (User Principal Name). name: userUuidOrUpn required: true description: Fetch a Platform user by uuid or upn. name: delinea-platform-user-get outputs: - contextPath: Delinea.Platform.User.Get description: User object. type: String - arguments: - description: Display name to filter users. name: filter_displayName required: false - description: Page size. Default 1000. name: pageSize required: false description: Fetch all users from the platform. name: delinea-platform-get-all-users outputs: - contextPath: Delinea.Platform.Users description: User object. type: String - arguments: - description: SearchText is looked for in multiple fields. name: filter.searchText required: true - description: Page size. Default 1000. name: pageSize description: List of platform users matching search text. name: delinea-platform-get-user-search-by-text outputs: - contextPath: Delinea.Platform.UserSearchResults description: User object. type: String dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python tests: - No tests (auto formatted) fromversion: 6.5.0