Skip to content
Check out this scri...
 
Notifications
Clear all

Check out this script for auto-revoking ZTNA access on offboarding.

1 Posts
1 Users
0 Reactions
33 Views
(@cloud_ops_amy)
Honorable Member
Joined: 7 months ago
Posts: 453
Topic starter   [#21254]

Hey everyone,

I was helping a client tighten up their offboarding process last week and realized how easy it is for ZTNA access to slip through the cracks if it's not automated. Manual ticket-based deprovisioning is slow and error-prone. So, I built a simple script that hooks into our HR system's termination webhook to automatically revoke ZTNA sessions and permissions.

The core idea is simple: when the offboarding event fires, the script calls the ZTNA provider's API to terminate active sessions and then removes the user from all access policies. We're using AWS with a popular ZTNA vendor, so I wrote it in Python for our Lambda function.

Here's the main part of the logic. It's generic enough to adapt to other vendors:

```python
def revoke_ztna_access(offboarded_user_email):
# 1. Terminate all active sessions for the user
sessions = ztna_client.get_active_sessions(offboarded_user_email)
for session in sessions:
ztna_client.terminate_session(session['id'])

# 2. Remove user from all ZTNA access groups/policies
user_groups = ztna_client.get_user_groups(offboarded_user_email)
for group in user_groups:
ztna_client.remove_user_from_group(offboarded_user_email, group['id'])

# 3. (Optional) Log and audit the action
audit_log_event({
'user': offboarded_user_email,
'action': 'ztna_access_revoked',
'timestamp': datetime.utcnow().isoformat()
})
```

**Key Integration Points:**
* The trigger is an EventBridge event from our HR platform (like Workday).
* The Lambda function needs the appropriate IAM role and ZTNA API credentials (secrets stored in AWS Secrets Manager).
* We also added a step to notify the security team via a Slack webhook for audit.

This automated approach has cut down our access revocation time from potentially hours/days to seconds. It's a small piece, but it's crucial for maintaining a true Zero Trust posture where access is truly "just-in-time."

Has anyone else built similar automation? I'm curious about how you handle the identity synchronization piece, especially with SCIM or from on-prem directories.

-- Amy


Cloud cost nerd. No, I don't use Reserved Instances.


   
Quote