---
title: Autonomous Cloud Response
description: "Set up Cloud Response in the AgileBlue Portal to disable and re-enable users across Office 365, AWS, Azure AD/Entra ID, and GCP, with permission steps.\n\nA shorter alternative (121 characters), if you’d rather not lean on the provider list:\n\nLearn how to configure cloud provider permissions and isolate or re-enable compromised user accounts from the AgileBlue Portal."
---

[Skip to content](https://help.agileblue.com/cloud-response#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)

# Autonomous Cloud Response

## Disable and re-enable cloud user accounts across Office 365, AWS, Azure AD/Entra ID, and GCP, directly from the AgileBlue Portal.

### Overview

Cloud Response lets you disable and re-enable a cloud identity without leaving the AgileBlue Portal. Setup happens in two stages: first you add credentials for each cloud provider you want to act against in **Settings \> Client Details**, then you isolate and re-enable individual users from the **Response** page. Credentials are entered separately for each provider, and isolation is provider scoped - isolating a user in one provider does not affect that user accounts in the others.

Separately, you can enable our autonomous response workflows for Cloud platforms – details on that setup can be found below.

---

### Configuring Cloud Provider Permissions

Before you add credentials in the AgileBlue Portal, each cloud provider needs an identity that AgileBlue can use to disable and re-enable users. Follow the steps below for each provider you plan to configure.

### Office 365

Follow the [Microsoft 365 Security Integration guide](https://help.agileblue.com/m365-security-integration?hsLang=en) to register the application and automatically input the necessary values.

### AWS

AWS setup has two parts: create a policy that grants the required permissions, then create a dedicated user with that policy and generate its access key.

#### Create the Policy

1. In the AWS console, go to **IAM \> Policies**.
2. Select **Create policy**.
3. In the Policy editor, select **JSON**.
4. Replace the contents of the editor with the following policy:
   
   ```
   {  "Version": "2012-10-17",  "Statement": [{    "Sid": "AgileBlueResponseUserContainment",    "Effect": "Allow",    "Action": [      "iam:GetUser", "iam:ListUsers",      "iam:ListAccessKeys", "iam:UpdateAccessKey",      "iam:ListUserPolicies", "iam:PutUserPolicy", "iam:DeleteUserPolicy"    ],    "Resource": "*"  }]}
   ```
5. Select **Next**.
6. Name the policy `AgileBlueResponseUserContainment`.
7. Select **Create policy**.

#### Create the User and Access Key

1. Go to **IAM \> Users**.
2. Select **Create user**.
3. Enter `agileblue-response` as the user name, then select **Next**.
4. Under **Permissions options**, select **Attach policies directly**.
5. Change the filter to **Customer managed**.
6. Find **AgileBlueResponseUserContainment** in the list, select its checkbox, then select **Next**.
7. Select **Create user**.
8. Find the new user in the list and select it.
9. Open the **Security credentials** tab.
10. Under **Access keys**, select **Create access key**.
11. Under **Use case**, select **Application running outside AWS**, then select **Next**.
12. Optionally, enter a description such as "AgileBlue auto response disable user credentials", then select **Create access key**.
13. Copy the **Access key** and **Secret access key**, and note the **Region** you want to use. The secret access key is shown only once, so make sure you copy it before leaving this page.

### Azure AD/Entra ID

If you have already configured the Office 365 integration, no additional setup is needed in Azure. In the **Cloud Provider Credentials** section of **Settings \> Client Details**, select **Copy from Office 365** to reuse those credentials for Azure AD/Entra ID.

### GCP

GCP setup takes place in two consoles: the Google Cloud console, where you create the service account, and the Google Admin console, where you grant it domain-wide delegation.

#### Part 1 - Google Cloud Console

Sign in to the [Google Cloud console](https://console.cloud.google.com/).

1. Select or create a project using the project selector in the top-left corner.
2. Go to **APIs & Services \> Library**, search for **Admin SDK API**, and select **Enable**.
3. Go to **IAM & Admin \> Service Accounts** and select **Create service account**. Name it `agileblue-response`, select **Create and continue**, skip the **Grant access** steps, and select **Done**.
4. Open the service account, go to the **Details** tab, and copy the **Unique ID** (a long number). You will need it in Part 2.
5. Go to the **Keys** tab and select **Add key \> Create new key**. Choose **JSON**, then select **Create**. A .json file downloads automatically. Keep this file private, as it is the credential you will upload to the AgileBlue Portal.

#### Part 2 - Google Admin Console

Sign in to the [Google Admin console](https://admin.google.com/) as a super admin.

1. Go to **Security \> Access and data control \> API controls**, select **Manage Domain Wide Delegation**, then select **Add new**.
2. For **Client ID**, enter the Unique ID you copied in Part 1, Step 4. For **OAuth scopes**, paste the following exactly (one line, no spaces), then select **Authorize**:
   
   ```
   https://www.googleapis.com/auth/admin.directory.user,https://www.googleapis.com/auth/admin.directory.user.security,https://www.googleapis.com/auth/admin.directory.user.readonly
   ```
3. ``Choose a delegated admin account that will act as a super admin (for example, admin@yourdomain.com). No changes are needed to that account. You will enter this email as the **Delegated admin email** in the AgileBlue Portal.

---

### Adding Cloud Provider Credentials

1. Log in to the AgileBlue Portal.
2. Navigate to **Settings**.
3. Select **Client Details**.
4. Locate the **Cloud Provider Credentials** section.
5. Enter the credentials for each provider you want to configure. Each provider requires the following: 
     1. **Office 365** - Directory (tenant) ID, Application (client) ID, Client secret (auto-populated during Office365 integration setup)
     2. **AWS** - Access key ID, Secret access key, Default region (select from the dropdown)
     3. **Azure AD/Entra ID** - Directory (tenant) ID, Application (client) ID, Client secret
     4. **GCP** - Service account JSON key, Delegated admin email

### Validating Your Credentials

1. After entering your provider credentials, select the **Validate Credentials** button.
2. Once your credentials are validated, scroll down to the **Update Client** button.
3. Select **Update Client**.

---

### Isolating a User

1. Navigate to the **Response** or **Case Details** page.
2. Locate the **Cloud Accounts** section.
3. Toggle to the provider that contains the user you want to isolate.
4. Find the user in the **Users** column.
5. Select the lock icon next to that user.
6. Enter any relevant notes when prompted.
7. Confirm the lock icon for that user now appears red, indicating the account is disabled.

---

### What Happens When You Isolate a User

Isolating a user runs the following actions against the targeted cloud identity in the selected provider:

1. **Account disablement** - The affected cloud identity is disabled immediately so it can no longer authenticate to that provider's services.
2. **Session and token revocation** - All active sessions, OAuth tokens, and short-lived credentials associated with the account are invalidated in real time.
3. **Third-party application revocation (GCP Specific)** - Third-party applications registered to, or signed in as, the affected users is revoked.
4. **Containment confirmation** - A timestamped containment event is recorded, indicating which actions were executed, which provider was targeted, and the outcome status (success or partial failure) for each step.

These actions are scoped to the provider you selected. To contain the same user in another cloud provider, toggle to that provider and isolate the user there as well.

---

### Re-Enabling a User

1. Navigate to the **Response** page.
2. Locate the **Cloud Accounts** section.
3. Toggle to the provider that contains the user you want to re-enable.
4. Find the user in the **Users** column and confirm the lock icon appears red.
5. Select the red lock icon.
6. Enter any relevant notes when prompted.
7. Confirm the lock icon for that user is no longer red, indicating the account is enabled.

---

### Reviewing a User's Enable and Disable History

1. Navigate to the **Response** page.
2. Locate the **Cloud Accounts** section.
3. Toggle to the provider that contains the user whose history you want to review.
4. Find the user in the **Users** column.
5. Select the dropdown icon to the left of the lock icon.
6. Review all previous enabling and disabling activity for that user, including: 
     1. Logs of each action
     2. Timestamps for each action
     3. Any notes entered at the time of the action

---

### Automating Cloud Response

Once your cloud provider credentials are validated, you can include each cloud platform in your autonomous response workflows, so AgileBlue contains affected cloud users without waiting for someone to isolate them manually. Autonomous cloud response is turned on per platform from **Settings \> Alert Playbook \> Autonomous Cloud Response**.

For full setup steps, see [Leverage The Power Of Autonomous Response](https://help.agileblue.com/autonomous-response?hsLang=en).

---

### Need Help?

If you have any questions about this feature, please don't hesitate to reach out. AgileBlue Support is also here to assist with any setup questions and can be reached at [support@agileblue.com](mailto:support@agileblue.com) or by submitting a ticket.

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue