Skip to content

Guardduty  >  Operations  >  disassociate_members

disassociate_members

Operation

disassociate_members async

disassociate_members(input: DisassociateMembersInput, plugins: list[Plugin] | None = None) -> DisassociateMembersOutput

Disassociates GuardDuty member accounts (from the current administrator account) specified by the account IDs.

When you disassociate an invited member from a GuardDuty delegated administrator, the member account details obtained from the CreateMembers API, including the associated email addresses, are retained. This is done so that the delegated administrator can invoke the InviteMembers API without the need to invoke the CreateMembers API again. To remove the details associated with a member account, the delegated administrator must invoke the DeleteMembers API.

With autoEnableOrganizationMembers configuration for your organization set to ALL, you'll receive an error if you attempt to disassociate a member account before removing them from your organization.

If you disassociate a member account that was added by invitation, the member account details obtained from this API, including the associated email addresses, will be retained. This is done so that the delegated administrator can invoke the InviteMembers API without the need to invoke the CreateMembers API again. To remove the details associated with a member account, the delegated administrator must invoke the DeleteMembers API.

When the member accounts added through Organizations are later disassociated, you (administrator) can't invite them by calling the InviteMembers API. You can create an association with these member accounts again only by calling the CreateMembers API.

Parameters:

Name Type Description Default
input DisassociateMembersInput

An instance of DisassociateMembersInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
DisassociateMembersOutput

An instance of DisassociateMembersOutput.

Input

DisassociateMembersInput dataclass

Dataclass for DisassociateMembersInput structure.

Attributes

account_ids class-attribute instance-attribute
account_ids: list[str] | None = None

A list of account IDs of the GuardDuty member accounts that you want to disassociate from the administrator account.

detector_id class-attribute instance-attribute
detector_id: str | None = None

The unique ID of the detector of the GuardDuty account whose members you want to disassociate from the administrator account.

Output

DisassociateMembersOutput dataclass

Dataclass for DisassociateMembersOutput structure.

Attributes

unprocessed_accounts class-attribute instance-attribute
unprocessed_accounts: list[UnprocessedAccount] | None = None

A list of objects that contain the unprocessed account and a result string that explains why it was unprocessed.