---
title: "POST /user/DisassociateUser"
method: POST
path: "/user/DisassociateUser"
---

# POST /user/DisassociateUser

`POST /user/DisassociateUser`

Disassociates the user from an EC2 instance providing user-based subscriptions.

## Request body

- object
  - `Username` string — The user name from the Active Directory identity provider for the user.
  - `InstanceId` string — The ID of the EC2 instance which provides user-based subscriptions.
  - `IdentityProvider` object — Refers to an identity provider.
    - `ActiveDirectoryIdentityProvider` object — The <code>ActiveDirectoryIdentityProvider</code> resource contains settings and other details about a specific Active Directory identity provider.
      - `DirectoryId` string — The directory ID for an Active Directory identity provider.
      - `ActiveDirectorySettings` object — The <code>ActiveDirectorySettings</code> resource contains details about the Active Directory, including network access details such as domain name and IP addresses, and the credential provider for user administration.
        - `DomainName` string — The domain name for the Active Directory.
        - `DomainIpv4List` IpV4[] — A list of domain IPv4 addresses that are used for the Active Directory.
        - `DomainIpv6List` IpV6[] — A list of domain IPv6 addresses that are used for the Active Directory.
        - `DomainCredentialsProvider` object — Points to the <code>CredentialsProvider</code> resource that contains information about the credential provider for user administration.
          - `SecretsManagerCredentialsProvider` object — Identifies the Secrets Manager secret that contains credentials needed for user administration in the Active Directory.
            - `SecretId` string — The ID of the Secrets Manager secret that contains credentials.
        - `DomainNetworkSettings` object — The <code>DomainNetworkSettings</code> resource contains an array of subnets that apply for the Active Directory.
          - `Subnets` Subnet[], required — Contains a list of subnets that apply for the Active Directory domain.
      - `ActiveDirectoryType` 'SELF_MANAGED' | 'AWS_MANAGED' — The type of Active Directory – either a self-managed Active Directory or an Amazon Web Services Managed Active Directory.
      - `IsSharedActiveDirectory` boolean — Whether this directory is shared from an Amazon Web Services Managed Active Directory. The default value is false.
  - `InstanceUserArn` string — The Amazon Resource Name (ARN) of the user to disassociate from the EC2 instance.
  - `Domain` string — The domain name of the Active Directory that contains information for the user to disassociate.

## Response `200`

Success

- DisassociateUserResponse
  - `InstanceUserSummary` object, required — Metadata that describes the associate user operation.
    - `Username` string, required — The user name from the identity provider for the user.
    - `InstanceId` string, required — The ID of the EC2 instance that provides user-based subscriptions.
    - `IdentityProvider` object, required — The <code>IdentityProvider</code> resource specifies details about the identity provider.
      - `ActiveDirectoryIdentityProvider` object — The <code>ActiveDirectoryIdentityProvider</code> resource contains settings and other details about a specific Active Directory identity provider.
        - `DirectoryId` string — The directory ID for an Active Directory identity provider.
        - `ActiveDirectorySettings` object — The <code>ActiveDirectorySettings</code> resource contains details about the Active Directory, including network access details such as domain name and IP addresses, and the credential provider for user administration.
          - `DomainName` string — The domain name for the Active Directory.
          - `DomainIpv4List` IpV4[] — A list of domain IPv4 addresses that are used for the Active Directory.
          - `DomainIpv6List` IpV6[] — A list of domain IPv6 addresses that are used for the Active Directory.
          - `DomainCredentialsProvider` object — Points to the <code>CredentialsProvider</code> resource that contains information about the credential provider for user administration.
            - `SecretsManagerCredentialsProvider` object — Identifies the Secrets Manager secret that contains credentials needed for user administration in the Active Directory.
              - …
          - `DomainNetworkSettings` object — The <code>DomainNetworkSettings</code> resource contains an array of subnets that apply for the Active Directory.
            - `Subnets` Subnet[], required — Contains a list of subnets that apply for the Active Directory domain.
        - `ActiveDirectoryType` 'SELF_MANAGED' | 'AWS_MANAGED' — The type of Active Directory – either a self-managed Active Directory or an Amazon Web Services Managed Active Directory.
        - `IsSharedActiveDirectory` boolean — Whether this directory is shared from an Amazon Web Services Managed Active Directory. The default value is false.
    - `Status` string, required — The status of a user associated with an EC2 instance.
    - `InstanceUserArn` string — The Amazon Resource Name (ARN) that identifies the instance user.
    - `StatusMessage` string — The status message for users of an EC2 instance.
    - `Domain` string — The domain name of the Active Directory that contains the user information for the product subscription.
    - `AssociationDate` string — The date a user was associated with an EC2 instance.
    - `DisassociationDate` string — The date a user was disassociated from an EC2 instance.

## Other responses

- `480` — ServiceQuotaExceededException
- `481` — ValidationException
- `482` — ConflictException
- `483` — ThrottlingException
- `484` — InternalServerException
- `485` — ResourceNotFoundException
- `486` — AccessDeniedException

---

[API](https://skmtc.net/aws/apis/license-manager-user-subscriptions.md) · [All operations](https://skmtc.net/aws/apis/license-manager-user-subscriptions/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/aws/license-manager-user-subscriptions/versions/3f333914dcdb/schema)
