Disable a User - Administrator Guide - 6.11 - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR Administrator Guide

Product
Cortex XSOAR
Version
6.11
Creation date
2022-12-12
Last date published
2024-04-15
Category
Administrator Guide
Abstract

Disable a user in Cortex XSOAR. All user information is retained for disabled users and they can be enabled again at a later date.

In Cortex XSOAR, you can temporarily disable or Remove a User. Users should be disabled if they need access at a later date. All user information is maintained for disabled users.

If the user is assigned to incidents or tasks or is the owner of a dashboard, these assignments do not automatically change when the user is disabled.

Tip

We recommend changing incident and task assignments manually before disabling users.

After you disable a user, any dashboards the user has created can only be deleted by the default admin via the API, using the dashboard ID. To get the dashboard ID, click on the gear icon on the relevant dashboard page, export the dashboard as a JSON file, and copy the dashboard ID from the file. Send a request to /dashboards/:id route. For example, DELETE /dashboards/9dd50ef1-8a2b-48a5-821e-8238a87e2bdc.

Any reports the user has created remain available. Reports are not owned by specific users and can be edited or deleted by other users.

Note

When a user is disabled, the user’s API keys are not revoked, as opposed to removing a user.

  1. Reassign incidents and tasks.

    1. Go to the Incidents page and search for -status:closed owner:user_name to find any incidents the user is assigned to. Reassign any open incidents to another user.

    2. Go to the Incidents page and search for -status:closed investigation.users:user_name. Reassign tasks to another user.

      When a user is assigned a task in an incident, the user is added to the incident. This search finds all incidents where the user is a participant.

  2. Disable the user.

    1. Go to SettingsUSERS AND ROLESUsers.

    2. Select the user you want to disable.

      If the user is a default admin, you need to select Roles and deselect Set as Default Admin.

    3. Click Disable.

    4. Confirm that you want to disable the user.