Files
splunk-security_content/playbooks/Azure_AD_Account_Unlocking.yml
2026-05-19 11:12:49 -07:00

27 lines
869 B
YAML

name: Azure AD Account Unlocking
id: c3c0157d-7da0-4dcb-8ba7-327ee91f531c
version: 2
creation_date: '2023-06-22'
modification_date: '2026-05-19'
author: Lou Stella, Splunk
type: Response
description: "Accepts user, to be enabled using Azure AD Graph connector. This playbook produces a normalized observables output for each user."
playbook: Azure_AD_Account_Unlocking
how_to_implement: This input playbook requires the Azure AD Graph connector to be configured. It is designed to work in conjunction with the Active Directory Enable Account Dispatch playbook or other playbooks in the same style.
references: []
app_list:
- Azure AD Graph
platform_tags:
- user
- D3-RUAA
- active_directory
- azure_ad_graph
- enable_account
playbook_type: Input
vpe_type: Modern
playbook_fields: []
product:
- Splunk SOAR
defend_technique_id:
- D3-RUAA