Block Account - Generic v2
This playbook blocks malicious usernames using all integrations that you have enabled. Supported integrations for this playbook: * Active Directory * PAN-OS - This requires PAN-OS 9.1 or higher. * SailPoint * PingOne * AWS IAM * Clarizen IAM * Envoy IAM * ExceedLMS IAM * Okta * Microsoft Graph User (Entra ID Users) * Google Workspace Admin * Slack IAM * ServiceNow IAM * Prisma Cloud IAM * Zoom IAM * Atlassian IAM * GitHub IAM.
- Pack
- CommonPlaybooks
- Tasks
- 64
Inputs
- Username — Array of malicious usernames to block.
- Tag — PAN-OS Tag name to apply to the username that you want to block.
- NamingConvention — In case you are using naming convention in your IDP, please specify a prefix for special/service accounts (use comma separated)
- UserVerification — Possible values:True/False. Default:True. Specify if User Verification is Requrired
Outputs
- Blocklist.Final — Blocked accounts.
Commands used
- ad-disable-account
- ad-get-user
- gsuite-user-update
- iam-disable-user
- identityiq-disable-account
- identityiq-get-accounts
- msgraph-user-account-disable
- msgraph-user-get
- pan-os-register-user-tag
- pingone-deactivate-user