functions/users/Lock-TssUser.ps1
function Lock-TssUser { <# .SYNOPSIS Lock a Secret Server User Account .DESCRIPTION Lock a Secret Server User Account .EXAMPLE $session = New-TssSession -SecretServer https://alpha -Credential $ssCred Lock-TssUser -TssSession $session -Id 28 Lock User 28 .LINK https://thycotic-ps.github.io/thycotic.secretserver/commands/users/Lock-TssUser .LINK https://github.com/thycotic-ps/thycotic.secretserver/blob/main/src/functions/users/Lock-TssUser.ps1 .NOTES Requires TssSession object returned by New-TssSession #> [CmdletBinding(SupportsShouldProcess)] param ( # TssSession object created by New-TssSession for authentication [Parameter(Mandatory, ValueFromPipeline, Position = 0)] [Thycotic.PowerShell.Authentication.Session] $TssSession, # User Id [Parameter(Mandatory, ValueFromPipelineByPropertyName)] [Alias('UserId')] [int[]] $Id ) begin { $tssParams = $PSBoundParameters $invokeParams = . $GetInvokeApiParams $TssSession } process { Write-Verbose "Provided command parameters: $(. $GetInvocation $PSCmdlet.MyInvocation)" if ($tssParams.ContainsKey('TssSession') -and $TssSession.IsValidSession()) { . $CheckVersion $TssSession '10.9.000000' $PSCmdlet.MyInvocation foreach ($user in $Id) { $uri = $TssSession.ApiUrl, 'users', $user -join '/' $invokeParams.Uri = $uri $invokeParams.Method = 'PATCH' $userBody = @{ isLockedOut = @{ dirty = $true value = $true } } $invokeParams.Body = $userBody | ConvertTo-Json if ($PSCmdlet.ShouldProcess("SecretId: $user", "$($invokeParams.Method) $uri with:`n$($invokeParams.Body)`n")) { Write-Verbose "Performing the operation $($invokeParams.Method) $uri with:`n$($invokeParams.Body)`n" try { $apiResponse = Invoke-TssApi @invokeParams $restResponse = . $ProcessResponse $apiResponse } catch { Write-Warning "Issue locking User [$user]" $err = $_ . $ErrorHandling $err } if ($restResponse.isLockedOut) { Write-Verbose "User [$user] locked out" } else { Write-Warning "User [$user] has not been locked out" } } } } else { Write-Warning 'No valid session found' } } } |