Configure Delinea Platform for Arctic Wolf Active Response

With the Active Response service, Arctic Wolf® can perform identity-based response actions in your network using Delinea Platform.

Delinea Platform supports these response actions:
  • Disable/Enable a user
  • Force a password reset

For more information, see Response action descriptions.

Note:

Configure this integration with your primary identity provider in a cloud-based environment. Arctic Wolf does not support hybrid or on-premises environments for identity-based response actions.

These resources are required:

  • A Delinea Platform service user account with the permissions required to disable and enable users and force password resets

  • Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.

Create a Delinea Platform service user

Arctic Wolf uses a Delinea Platform service user account to authenticate and perform identity response actions on your behalf.

  1. Sign in to the Delinea Platform. For example, https://your-tenant.delinea.app.
  2. Navigate to Users.
  3. Click More > Add service user.
  4. Complete the required fields:
    • Username — Enter a unique identifier for the service user. This value is used as the Client ID when you provide credentials to Arctic Wolf.
    • Display name — Enter a descriptive name that reflects the purpose of the service user.
    • Set password — Set a secure password. This value is used as the Client Secret when you provide credentials to Arctic Wolf.
  5. Save the service user.
  6. Verify that the service user appears in the Users list with the correct groups and permissions.
CAUTION:

The service user account must remain active and enabled at all times. If this account is disabled, Active Response actions fail and the integration becomes unhealthy. Use a dedicated service account that is excluded from automated response actions.

Configure Delinea Platform user management permissions

Assign the permissions required for Arctic Wolf Active Response to the Delinea Platform service user.

  1. In Delinea Platform, navigate to Access > Roles.
  2. Create a new role or edit an existing role.
  3. Add this permission to the role: delinea.platform/identity/admin/manage.
  4. Assign the role to a group.
  5. Add the service user to that group.

Provide Delinea Platform Active Response credentials to Arctic Wolf

Enter your Delinea Platform service user credentials in the Arctic Wolf Unified Portal to enable Active Response.

  1. Sign in to the Portail unifié Arctic Wolf.
  2. In the navigation menu, click Organization Profile > Integrations.
  3. On the Active Response tab, click New Active Response Integration +.
  4. Click Delinea.
  5. On the New Active Response Integration page, configure these settings:
    • Integration Name — Enter a unique and descriptive name for the integration.
    • Base URL — Enter the URL of your Delinea Platform tenant. For example, https://your-tenant.delinea.app.
    • Client ID — Enter the username of the service user that you created.
    • Client Secret — Enter the password of the service user you created.
  6. Click Save Integration.
  7. Verify that the integration status shows as healthy.
Note:

When a password reset action is performed, you may receive an invitation-style email from Delinea Platform prompting you to accept access to the tenant, like the example provided here. This is expected behavior.

Example of an invitation-style email from Delinea Platform