Does the "Disable after Inactive for n Days" Global Setting affect API User IDs?
説明
Is the "Disable after Inactive for n Days" Global Setting only for Web Users, or does it apply to CLI/API users as well?
対策
This setting applies to all types of User IDs and the "Disabled" flag will be set on the User after the the configured number of inactive days. However, it may have a different affect on Web Users versus CLI/API users.
For Web Users that are marked as Disabled, they will no longer be able to login through the TPAM web interface.
For API Users, they will show as Disabled on the User Management page, but their public key will not be removed. So it is possible that an API User will still be able to authenticate with their key and perform tasks, even though they Disabled flag has been set.
If you wish to re-enable the API User, the "User Disabled" box will be showed as greyed out in the web interface, however, you should be able to clear it by making an update to the User Details and saving the changes, or batch updating the user and setting the Disabled column to "N"