Everything You Need to Know

User Management

User

Estimated reading: 8 minutes 110 views

Overview

The User menu is used to manage OneDB Admin Console users.

Administrators can use this menu to create and manage user accounts that are allowed to access the OneDB Admin Console. Each user can be assigned to a group, which determines the user’s access level and administrative permissions within OneDB.

Main Functions

Administrators can use the User menu to:

  • View registered users
  • Add a new user
  • Assign a user to a group
  • Define user login credentials
  • Edit existing user information
  • Delete unused user accounts
  • Review user information such as username, name, email, and group

User Management

The User Management page displays the list of users configured in OneDB.

This page allows administrators to review existing users and access the user creation function.

User Management Table

The user list may display the following information:

Column Description
Username The login name used by the user to access OneDB.
First Name The user’s first name.
Last Name The user’s last name.
Email The user’s email address.
Group The group assigned to the user.
MFA Status Indicates whether the user has completed MFA enrollment.
Actions Allows authorized administrators to edit the user, delete the account, or reset MFA where available.

If there are no users displayed in the table, the page may show:

No data available in table

MFA Status

The MFA Status column shows whether a user has enrolled Multi-Factor Authentication (MFA) for OneDB Admin Console access.

MFA Status Description
Not Enrolled The user has not yet completed MFA enrollment.
Enrolled The user has completed MFA enrollment and can use their configured authenticator application during login.

MFA adds an additional verification step after the user enters their username and password. This helps protect OneDB Admin Console access if a password is exposed or compromised.

MFA availability and enforcement depend on the MFA configuration and the user’s assigned group policy.

MFA Enrollment

When MFA is required for a user, the user must complete MFA enrollment during login.

The enrollment process typically includes:

  1. Sign in to the OneDB Admin Console using the assigned username and password.
  2. Open the MFA enrollment page when prompted.
  3. Scan the displayed QR code using a supported authenticator application.
  4. Enter the verification code generated by the authenticator application.
  5. Complete the verification.

After successful verification, the user’s MFA Status changes to Enrolled.

Each user should enroll MFA using their own authenticator application. Authenticator devices or MFA codes should not be shared between administrators.

Add User

The User Add page is used to create a new OneDB Admin Console user.

Administrators must provide the user identity, assign the user to a group, and define the user password.

User Add Fields

Field Description
Username The login name used by the user to access the OneDB Admin Console.
First Name The user’s first name.
Last Name The user’s last name.
Email The user’s email address.
Group The group assigned to the user. The group determines the user’s access permissions.
Password The password used by the user to log in.
Confirm Password Confirmation of the password value. This must match the Password field.
Submit Saves the new user account.

Username

The Username field defines the login name for the user.

Example:

johny
admin.operator
security.admin

Recommended practice:

Recommendation Description
Use unique usernames Each administrator should have a dedicated user account.
Avoid shared accounts Do not share one account between multiple administrators.
Use clear naming Use naming that can be traced to an individual or operational role.

First Name and Last Name

The First Name and Last Name fields identify the user in the OneDB Admin Console.

These fields help administrators recognize who owns the account, especially when reviewing users or audit trail records.

Example:

First Name: Johny
Last Name: Johny

Email

The Email field stores the user’s email address.

This may be used for identification, notification, or administrative reference depending on the enabled OneDB features.

Example:

johny@company.com

Group

The Group field assigns the user to a user group.

A group determines the user’s access level and permission scope within OneDB. Before creating a user, ensure that the required group has already been created in the Group menu.

Example group:

Admin

Common group examples may include:

Group Description
Admin Full administrative access to OneDB.
Operator Operational access for monitoring or routine administration.
Auditor Read-only or audit-focused access, depending on group configuration.
Security Admin Access to security-related configuration such as keys, masks, templates, and audit review.

Available groups depend on the group configuration defined in OneDB.

Password and Confirm Password

The Password field defines the user’s login password.

The Confirm Password field must match the Password field before the user can be created.

Password requirements may depend on the password policy configured in Site Configurations.

Password policy may include:

Requirement Description
Minimum password length The password must meet the configured minimum number of characters.
Uppercase letters The password may be required to contain uppercase letters.
Lowercase letters The password may be required to contain lowercase letters.
Numbers The password may be required to contain numeric characters.
Special characters The password may be required to contain special characters.

How to Add a User

  1. Open User from the User Management menu.
  2. Click Add user.
  3. Enter the Username.
  4. Enter the First Name.
  5. Enter the Last Name.
  6. Enter the Email address.
  7. Select the user Group.
  8. Enter the Password.
  9. Re-enter the same value in Confirm Password.
  10. Click Submit.

How to Edit a User

  1. Open User from the User Management menu.
  2. Find the user that needs to be updated.
  3. Click the Edit icon, if available.
  4. Modify the required user information.
  5. Save the changes.

How to Delete a User

  1. Open User from the User Management menu.
  2. Find the user that should be removed.
  3. Click the Delete icon, if available.
  4. Confirm the deletion if prompted.

Before deleting a user, ensure that the account is no longer required for administration, audit review, or operational responsibility.

Reset MFA

Administrators can reset MFA for a user from the User Edit page.

Resetting MFA removes the user’s existing MFA enrollment. The user must enroll again during their next login when MFA is required.

Use MFA reset when:

Situation Recommended Action
User changed or lost their phone Reset MFA and ask the user to enroll again.
User replaced their authenticator application Reset MFA and require new enrollment.
MFA device is no longer trusted Reset MFA immediately.
User cannot complete MFA verification Confirm the user’s identity, then reset MFA if necessary.

How to Reset MFA

  1. Open User from the User Management menu.
  2. Find the user whose MFA enrollment needs to be removed.
  3. Click the Edit icon.
  4. Review the current MFA Status.
  5. Click Reset MFA.
  6. Confirm the reset when prompted.
  7. Inform the user that MFA enrollment is required again at the next login.

Resetting MFA does not change the user’s username, password, group assignment, or other profile details. It only removes the existing MFA enrollment.

MFA Recommended Practice

Recommendation Description
Require MFA for privileged users Apply MFA to administrator and security-sensitive accounts.
Use individual user accounts Each administrator should use their own account and authenticator application.
Verify identity before resetting MFA MFA reset can restore account access, so administrators should validate the user’s identity first.
Reset MFA promptly for lost devices Remove enrollment immediately when a registered device is lost, stolen, or no longer trusted.
Avoid shared authenticator devices Shared MFA devices reduce accountability and weaken access control.
Review MFA status regularly Periodically review users who remain in Not Enrolled status when MFA is expected.

Important Notes

  • User accounts are used to access the OneDB Admin Console.
  • Each user should be assigned to the appropriate group based on their responsibility.
  • Group assignment controls the user’s access scope and permissions within OneDB.
  • Password requirements are controlled by the password policy configured in Site Configurations.
  • Individual user accounts are recommended for accountability and auditability.
  • Shared administrator accounts should be avoided because they make it harder to identify who performed a specific action.
  • User activity may be recorded in Audit Trail, depending on the action performed and the enabled audit behavior.
  • Access to the User menu should be limited to authorized administrators only.

Recommended Practice

Recommendation Description
Use individual accounts Create a separate account for each administrator.
Avoid shared users Shared accounts reduce accountability and audit visibility.
Assign proper groups Assign users to groups based on their job responsibility.
Apply least privilege Give users only the access they need.
Use strong passwords Follow the configured password policy and organizational security standard.
Review users regularly Remove or disable accounts that are no longer required.
Monitor activity Review Audit Trail for important administrative actions.
Share this Doc

User

Or copy link

Table of Contents