NOTE: "Administrator (Unified Management)" role is required to disable any user. Administrator role can disable any user excet users with the "Administrator (Unified Management)" role
From the console menu bar, select the configuration (gear) icon > Login Accounts
Select Login Accounts > Users
Select the "View Details" icon next to the username
Under Account > Statues, select "Disabled"
Click Save at the bottom of the page
Additional Information
Console login accounts created through AD mapping cannot be disabled directly. The only way to disable an AD account is to change the mapping rules for their AD security group so that they are mapped to user role that is disabled or has no privileges.
Further information can be found in the "Managing Console Login Accounts" section of https://community.carbonblack.com/t5/Documentation-Downloads/VMware-Carbon-Black-App-Control-User-Guide-v8-6/ta-p/99694