Users General Information
The Users contains the List of users and displays all enrolled users of a specific tenant. Also, the list of partially enrolled users (where the enrollment was started but is still not finished) can be displayed.
Available actions for users with appropriate privileges:
[ click on the row ] |
Display user details allows the operator to display all necessary details needed for the overall view of each user. |
|
Onboarding invitational process where an operator can invite a user to MAYI ID in two ways:
|
||
Display partially enrolled users |
By default, fully registered users are displayed. By changing the box, it is then possible to display only partially registered users, i.e. users whose registration has been started but for some reason has not been completed, or who have been unregistered by the operator. For such users it is possible to use the Complete enrollment function - see below. |
|
Search |
Search for the specific user by using the username, first name or last name. |
|
The feature is available only for partially enrolled users - an operator can use it and finish the user's enrollment on behalf of a user. The enrollment process is done by the operator on behalf of the user. In specific cases, it is also possible for the operator from one tenant to enrol the user to another tenant (in case the operator has all requested permissions and privileges defined on the target tenant side). |
||
Emergency access is a feature that allows an operator to generate a special one-time password (OTP) for a user who has lost all means of authentication using a second factor - for example, a lost mobile phone. The OTP generated in this way has limited validity and gives the user the possibility to log in to the application and perform the necessary actions to register new second-factor authentication methods (for example, registration of new tokens on a new mobile phone, etc.). An emergency access code could be also used as an approval method. Note: The emergency code can be used to log in as a replacement for a standard OTP or as part of the approval process. Its validity is defined based on a template, BUT this code is deactivated when any of the following operations are performed:
|
||
Display the user's magic questions and answers. |
||
The user authentication feature is used by operators to verify the identity of the caller. It consists of sending a specifically generated OTP in a chosen way (for example to a mobile phone) and its return verification during communication with the caller. If the OTP communicated by the user is correct, it can be assumed that he is who he claims to be. |
||
A feature used by an operator to unlock a user account locked in MAYI ID - OTP auth application. Users can lock due to multiple wrong password inputs. |
||
A feature used by an operator to immediately update of user from an external resource (first name, last name, status etc). |
||
|
A feature used by an operator to enable disabled users or to disable active users in AD. |
|
Un-enroll user feature allows an operator to delete an enrolled user from the system in case of any problems with user configurations. During the deletion, all user data and enrolled tokens are removed from the database and relevant storage. The user receives an email with information about the link to make a new enrollment. |
||
Permanently delete the user from the system and source LDAP as well - depending on the admin's configuration. |
||
Reorder and Hide Table Columns
|
Simple interface for column organisation. |
Invite new user - Import user from LDAP
1 |
Open the Users option in the Operational Console menu. |
|
2 |
A list of the tenant's users will be displayed. |
|
3 |
Press the INVITE NEW USER button [].
|
|
4 |
The modal window with the list of onboarding templates will be displayed. In this selection, only the LDAP type on invitation templates is displayed. |
|
5 |
Select the Import existing user choice, choose the template from the list and press the button NEXT. The templates are configured in the IGA - Governance console by the user with a specific privilege |
|
6 |
Insert the username of the new user and press the NEXT button. As the invitation is based on LDAP so username must exist in LDAP, otherwise, the invitation will be stopped with the "User does not exist" message. |
|
7 |
A modal window with the details of the user will be displayed. Check the email address for the invitation and press the SEND INVITATION button
|
|
8 |
Invitation email will be sent to the specified email address. So the user can start the onboarding process. |
Invite new user - Create a new user
1 |
Switch to the relevant Tenant, and open the Users option in the Operational Console menu. |
|
2 |
A list of the tenant's users will be displayed. |
|
3 |
||
4 |
The modal window with the list of onboarding templates will be displayed. In this selection, only EXT type on invitation templates - see Invitation configuration page for more details. |
|
5 |
Select the Select new user choice, choose the template from the list and press the button NEXT. The templates are configured in the IGA - Governance console by the user with specific privilege - see Invitation configuration page for more details. |
|
6 |
The invitation form will be displayed. The scope of the invitation form is defined on the template level - see the Invitation configuration page for more details. |
|
7 |
Fill in the requested information and the finish of the invitation process ends with the following variants - depending on the configuration and operator's permissions and privileges: |
|
8 |
Variant A - operator has:
so the CONTINUE button will create a user in LDAP and also in the MAYI ID database and start the enrollment on behalf process. |
|
9 |
Variant B - operator has only:
but doesn't have permission for any enrollment profile so the CONFIRM button will create a user in the LDAP and the MAYI ID database - the user will be available on the list of users as partially enrolled. |
Enroll new user - Enrollment on behalf
1 |
This function could be run as a part of the invitation process (see above - Invite new user - Create new user) OR as a stand-alone feature from the Users list in the Operational console - open the Users menu option in the Operational Console menu, switch to Partially enrolled users and use the Complete enrollment menu option from the context menu |
|
2 |
The first step of enrollment on-behalf form will be displayed.
|
|
3 |
Fill in all mandatory fields and press the CONTINUE button. |
|
4 |
The second step of enrollment on-behalf form is displayed. This step contains the enrollment of tokens. Press the ADD NEW TOKEN button [] to select which type of token should be enrolled - see the token enrollment help page The types of tokens that could be enrolled are defined on the administrator level. |
|
5 |
Enrol the required number of tokens and press the ENROLL USER button. |
|
6 |
The user is enrolled in MAYI ID and capable of log-in using the enrolled token. |
The configuration of the enrollment profile is done in the Admin console on the Enrollment configuration menu option - see the Enrollment configuration documentation page.
Display user detail
1 |
Open the Users menu option in the Operational Console menu. |
2 |
A list of the tenant's users will be displayed. |
3 |
Search for the desired user - you can use the Search function - and mouse-click on the selected row. Search is possible by username, first name or last name |
4 |
The drawer with the details of the user will be displayed on the right side of the screen - for detailed help please visit the User detail help page |