category: Authentication & Identity Management provider: Amazon commonfields: id: AWS-ILM version: -1 configuration: - display: Base URL name: url required: true type: 0 - display: Tenant ID name: credentials type: 9 displaypassword: Authentication Token required: false - display: Tenant ID name: tenant_id type: 0 hidden: true required: false - display: Authentication Token name: authentication_token type: 4 hidden: true required: false - defaultvalue: 'true' display: Allow creating users name: create_user_enabled type: 8 required: false - defaultvalue: 'true' display: Allow updating users name: update_user_enabled type: 8 required: false - defaultvalue: 'true' display: Allow enabling users name: enable_user_enabled type: 8 required: false - defaultvalue: 'true' display: Allow disabling users name: disable_user_enabled type: 8 required: false - defaultvalue: 'true' display: Automatically create user if not found in update command name: create_if_not_exists type: 8 required: false - defaultvalue: User Profile - SCIM (Incoming) display: Incoming Mapper name: mapper_in required: true type: 0 - defaultvalue: User Profile - SCIM (Outgoing) display: Outgoing Mapper name: mapper_out required: false type: 0 hidden: - marketplacev2 - platform additionalinfo: Cortex XSOAR only parameter. - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false description: Integrate with AWS's services to execute CRUD and Group operations for employee lifecycle processes. display: AWS - IAM (user lifecycle management) name: AWS-ILM script: commands: - arguments: - description: User Profile indicator details. name: user-profile required: true - auto: PREDEFINED defaultValue: 'true' description: 'When set to true, after the command execution the status of the user in the 3rd-party integration will be active. Possible values: "true" and "false".' name: allow-enable predefined: - 'true' - 'false' description: Creates a user. execution: true name: iam-create-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String - arguments: - description: A User Profile indicator. name: user-profile required: true - auto: PREDEFINED defaultValue: 'true' description: 'When set to true, after the command execution the status of the user in the 3rd-party integration will be active. Possible values: "true" and "false".' name: allow-enable predefined: - 'true' - 'false' description: Updates an existing user with the data passed in the user-profile argument. execution: true name: iam-update-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String compliantpolicies: - User Hard Remediation - arguments: - description: A User Profile indicator. name: user-profile required: true description: Retrieves a single user resource. name: iam-get-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String - arguments: - description: A User Profile indicator. name: user-profile required: true description: Disable an active user. execution: true name: iam-disable-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String compliantpolicies: - User Hard Remediation - description: Retrieves a User Profile schema, which holds all of the user fields within the application. Used for outgoing-mapping through the Get Schema option. name: get-mapping-fields - name: iam-get-group description: Retrieves a group. execution: true arguments: - name: scim required: true description: SCIM content in JSON format. outputs: - contextPath: GetGroup.id description: Group Id. type: String - contextPath: GetGroup.displayName description: Display name of the group. type: String - contextPath: GetGroup.members.display description: Display name of the group member. type: String - contextPath: GetGroup.members.value description: ID of the group member. type: String - contextPath: GetGroup.success description: Success status of the command. type: Boolean - contextPath: GetGroup.errorCode description: Error code if there is a failure. type: Number - contextPath: GetGroup.errorMessage description: Error details if there is a failure. type: Unknown - name: iam-create-group arguments: - name: scim required: true description: Group SCIM data with the display name. outputs: - contextPath: CreateGroup.id description: Group ID. type: String - contextPath: CreateGroup.displayName description: Display name of the group. type: String - contextPath: CreateGroup.success description: Success status of the command. type: Boolean - contextPath: CreateGroup.errorCode description: Error code if there is a failure. type: Number - contextPath: CreateGroup.errorMessage description: Error details if there is a failure. type: Unknown description: Creates an empty group. execution: true - name: iam-update-group arguments: - name: scim required: true description: Group SCIM data. - name: memberIdsToAdd auto: PREDEFINED predefined: - Comma-separated optional values. description: List of members IDs. A maximum of 100 users per call can be modified using this command. isArray: true - name: memberIdsToDelete auto: PREDEFINED predefined: - Comma-separated optional values. description: List of members ids to be deleted from the group. A maximum of 100 users per call can be modified using this command. isArray: true outputs: - contextPath: UpdateGroup.id description: Group ID. type: String - contextPath: UpdateGroup.displayName description: Display name of the group. type: String - contextPath: UpdateGroup.success description: Success status of the command. type: Boolean - contextPath: UpdateGroup.errorCode description: Error code if there is a failure. type: Number - contextPath: UpdateGroup.errorMessage description: Error details if there is a failure. type: Unknown description: Updates an existing group resource. This command allows individual (or groups of) users to be added or removed from the group with a single operation. A maximum of 100 users can be modified in a single call. execution: true - name: iam-delete-group arguments: - name: scim required: true description: Group SCIM with ID. outputs: - contextPath: DeleteGroup.id description: Group ID. type: String - contextPath: DeleteGroup.displayName description: Display name of the group. type: String - contextPath: DeleteGroup.success description: Success status of the command. type: Boolean - contextPath: DeleteGroup.errorCode description: Error code if there is a failure. type: Number - contextPath: DeleteGroup.errorMessage description: Error details if there is a failure. type: Unknown description: Permanently removes a group. execution: true dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python ismappable: true isremotesyncout: true tests: - No tests fromversion: 6.0.0