category: Identity and Access Management provider: Slack sectionorder: - Connect - Collect commonfields: id: Slack IAM version: -1 configuration: - name: credentials type: 9 displaypassword: Access Token hiddenusername: true required: false - display: Access Token name: access_token type: 4 section: Connect hidden: true required: false - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - additionalinfo: If set to false, iam-create-user command will be skipped, and user will not be created. defaultvalue: 'true' display: Allow creating users name: create_user_enabled type: 8 section: Collect advanced: true required: false - defaultvalue: 'true' display: Allow updating users name: update_user_enabled type: 8 section: Collect advanced: true required: false - defaultvalue: 'true' display: Allow enabling users name: enable_user_enabled type: 8 section: Collect advanced: true required: false - defaultvalue: 'true' display: Allow disabling users name: disable_user_enabled type: 8 section: Collect advanced: true required: false - defaultvalue: 'true' display: Automatically create user if not found in update command name: create_if_not_exists type: 8 section: Collect advanced: true required: false - defaultvalue: User Profile - SCIM (Incoming) display: Incoming Mapper name: mapper_in required: true type: 0 section: Connect - defaultvalue: User Profile - SCIM (Outgoing) display: Outgoing Mapper name: mapper_out required: false type: 0 section: Connect additionalinfo: Cortex XSOAR only parameter. hidden: - marketplacev2 - platform description: Integrate with Slack's services to execute CRUD operations for employee lifecycle processes. display: Slack IAM name: Slack IAM script: commands: - arguments: - description: User Profile indicator details. name: user-profile required: true - auto: PREDEFINED defaultValue: 'true' description: When set to true, after the command execution the status of the user in the 3rd-party integration will be active. name: allow-enable predefined: - 'true' - 'false' description: Creates a user. execution: true name: iam-create-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String - arguments: - description: A User Profile indicator. name: user-profile required: true - auto: PREDEFINED defaultValue: 'true' description: When set to true, after the command execution the status of the user in the 3rd-party integration will be active. name: allow-enable predefined: - 'true' - 'false' description: Updates an existing user with the data passed in the user-profile argument. execution: true name: iam-update-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String compliantpolicies: - User Hard Remediation - arguments: - description: A User Profile indicator. name: user-profile required: true description: Retrieves a single user resource. name: iam-get-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String - arguments: - description: A User Profile indicator. name: user-profile required: true description: Disable an active user. execution: true name: iam-disable-user outputs: - contextPath: IAM.Vendor.active description: When true, indicates that the employee's status is active in the 3rd-party integration. type: Boolean - contextPath: IAM.Vendor.brand description: Name of the integration. type: String - contextPath: IAM.Vendor.details description: Provides the raw data from the 3rd-party integration. type: string - contextPath: IAM.Vendor.email description: The employee's email address. type: String - contextPath: IAM.Vendor.errorCode description: HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: Reason why the API failed. type: String - contextPath: IAM.Vendor.id description: The employee's user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: Name of the integration instance. type: string - contextPath: IAM.Vendor.success description: When true, indicates that the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee's username in the app. type: String compliantpolicies: - User Hard Remediation - description: Retrieves a User Profile schema, which holds all of the user fields within the application. Used for outgoing-mapping through the Get Schema option. name: get-mapping-fields - arguments: - description: Group SCIM data with displayName. name: scim required: true description: Creates an empty group. name: iam-create-group outputs: - contextPath: CreateGroup.id description: ID of the group. type: String - contextPath: CreateGroup.displayName description: The display name of the group. type: String - contextPath: CreateGroup.success description: Indicates whether the command succeeded. type: Boolean - contextPath: CreateGroup.errorCode description: HTTP error response code. type: Number - contextPath: CreateGroup.errorMessage description: Reason why the API failed. type: String - arguments: - description: Group SCIM Data. name: scim required: true - auto: PREDEFINED defaultValue: 'false' description: Wheather to include group's members. name: includeMembers predefined: - 'true' - 'false' description: Retrieves the group information including members. name: iam-get-group outputs: - contextPath: GetGroup.id description: ID of the group. type: String - contextPath: GetGroup.displayName description: The display name of the group. type: String - contextPath: GetGroup.members.display description: The display name of the group member. type: String - contextPath: GetGroup.members.value description: ID of the group member. type: String - contextPath: GetGroup.success description: Indicates whether the command succeeded. type: Boolean - contextPath: GetGroup.errorCode description: HTTP error response code. type: Number - contextPath: GetGroup.errorMessage description: Reason why the API failed. type: String - arguments: - description: Group SCIM with id in it. name: scim required: true description: Permanently removes a group. name: iam-delete-group outputs: - contextPath: DeleteGroup.id description: ID of the group. type: String - contextPath: DeleteGroup.displayName description: The display name of the group. type: String - contextPath: DeleteGroup.success description: Indicates whether the command succeeded. type: Boolean - contextPath: DeleteGroup.errorCode description: HTTP error response code. type: Number - contextPath: DeleteGroup.errorMessage description: Reason why the API failed. type: String - arguments: - description: Group SCIM data. name: scim required: true - description: List of members ids to add. A maximum of 15,000 users per call can be modified using this command. isArray: true name: memberIdsToAdd - description: List of members ids to be deleted from the group. A maximum of 15,000 users per call can be modified using this command. isArray: true name: memberIdsToDelete description: Updates an existing group resource. This command allows individual (or groups of) users to be added or removed from the group with a single operation. A max of 15,000 users can be modified in 1 call. name: iam-update-group outputs: - contextPath: UpdateGroup.id description: ID of the group. type: String - contextPath: UpdateGroup.displayName description: The display name of the group. type: String - contextPath: UpdateGroup.success description: Indicates whether the command succeeded. type: Boolean - contextPath: UpdateGroup.errorCode description: HTTP error response code. type: Number - contextPath: UpdateGroup.errorMessage description: Reason why the API failed. type: String dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python ismappable: true isremotesyncout: true tests: - No tests fromversion: 6.0.0 supportedModules: - xsiam - agentix - edr - cloud - cloud_runtime_security