<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Stroom – account</title>
    <link>/tags/account/</link>
    <description>Recent content in account on Stroom</description>
    <generator>Hugo -- gohugo.io</generator>
    <lastBuildDate>Fri, 01 Nov 2024 00:00:00 +0000</lastBuildDate>
    
	  <atom:link href="/tags/account/index.xml" rel="self" type="application/rss+xml" />
    
    
      
        
      
    
    
    <item>
      <title>Docs: User Accounts</title>
      <link>/docs/user-guide/security/user-accounts/</link>
      <pubDate>Fri, 01 Nov 2024 00:00:00 +0000</pubDate>
      
      <guid>/docs/user-guide/security/user-accounts/</guid>
      <description>
        
        
        
&lt;div class=&#34;alert alert-warning&#34; role=&#34;alert&#34;&gt;
&lt;h4 class=&#34;alert-heading&#34;&gt;TODO&lt;/h4&gt;

    The Users, Groups and Permissions screens are undergoing significant change in Stroom v7.6.
Therefore this section will be updated with more detail in v7.6.

&lt;/div&gt;


&lt;div class=&#34;alert alert-primary&#34; role=&#34;alert&#34;&gt;
&lt;h4 class=&#34;alert-heading&#34;&gt;Note&lt;/h4&gt;



    &lt;p&gt;If Stroom is configured to use an external &lt;span class=&#34;glossary-link&#34;&gt;
&lt;a href=&#34;../../docs/glossary/i/glossary-idp&#34;&gt;
&lt;span&gt;Identity Provider (IDP)&lt;/span&gt;
&lt;i class=&#34;glossary-link-icon fas fa-book fa-sm text-primary&#34;&gt;&lt;/i&gt;
&lt;/a&gt;&lt;span class=&#34;glossary-tooltip&#34;&gt;
&lt;span class=&#34;glossary-tooltip-title&#34;&gt;Identity Provider (IDP)&lt;/span&gt;
&lt;span class=&#34;glossary-tooltip-summary&#34;&gt;An &lt;strong&gt;Id&lt;/strong&gt;entity &lt;strong&gt;P&lt;/strong&gt;rovider is a system or service that can authenticate a user and assert their identity. &lt;em&gt;Identity providers&lt;/em&gt; can support single sign on (SSO), which allows the user to sign in once to the &lt;em&gt;Identity Provider&lt;/em&gt; so they are then authenticated to all systems using that IDP.&lt;/span&gt;&lt;span class=&#34;glossary-tooltip-truncated&#34;&gt;Click to see more details…&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; (e.g. Azure Active Directory or AWS Cognito) then all user accounts are managed within that &lt;span class=&#34;glossary-link&#34;&gt;
&lt;a href=&#34;../../docs/glossary/i/glossary-idp&#34;&gt;
&lt;span&gt;Identity Provider (IDP)&lt;/span&gt;
&lt;i class=&#34;glossary-link-icon fas fa-book fa-sm text-primary&#34;&gt;&lt;/i&gt;
&lt;/a&gt;&lt;span class=&#34;glossary-tooltip&#34;&gt;
&lt;span class=&#34;glossary-tooltip-title&#34;&gt;Identity Provider (IDP)&lt;/span&gt;
&lt;span class=&#34;glossary-tooltip-summary&#34;&gt;An &lt;strong&gt;Id&lt;/strong&gt;entity &lt;strong&gt;P&lt;/strong&gt;rovider is a system or service that can authenticate a user and assert their identity. &lt;em&gt;Identity providers&lt;/em&gt; can support single sign on (SSO), which allows the user to sign in once to the &lt;em&gt;Identity Provider&lt;/em&gt; so they are then authenticated to all systems using that IDP.&lt;/span&gt;&lt;span class=&#34;glossary-tooltip-truncated&#34;&gt;Click to see more details…&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; and the Manage Accounts screen in Stroom will not be available.
For more details about external Identity Providers, see &lt;a href=&#34;../../docs/install-guide/setup/open-id/&#34;&gt;Open ID Connect&lt;/a&gt;.&lt;/p&gt;


&lt;/div&gt;


&lt;h2 id=&#34;accounts-vs-stroom-users&#34;&gt;Accounts vs Stroom Users&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&#34;../../docs/install-guide/setup/open-id/accounts-users/&#34;&gt;Accounts vs Users&lt;/a&gt; for details on the difference between a Stroom User Account and a Stroom User.&lt;/p&gt;
&lt;h2 id=&#34;creating-user-accounts&#34;&gt;Creating User Accounts&lt;/h2&gt;
&lt;p&gt;User accounts can only be created by a user that holds the &lt;code&gt;Manage Users&lt;/code&gt; or &lt;code&gt;Administrator&lt;/code&gt; &lt;span class=&#34;glossary-link&#34;&gt;
    &lt;a href=&#34;../../docs/glossary/a/glossary-application-permission&#34;&gt;
      &lt;span&gt;Application permission&lt;/span&gt;
      &lt;i class=&#34;glossary-link-icon fas fa-book fa-sm text-primary&#34;&gt;&lt;/i&gt;
    &lt;/a&gt;&lt;span class=&#34;glossary-tooltip&#34;&gt;
      &lt;span class=&#34;glossary-tooltip-title&#34;&gt;Application permission&lt;/span&gt;
      &lt;span class=&#34;glossary-tooltip-summary&#34;&gt;This is a permission that is not specific to a single document. It applies to all documents or is not related to documents in any way.&lt;/span&gt;&lt;span class=&#34;glossary-tooltip-truncated&#34;&gt;Click to see more details...&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;Create a new user account by selecting&lt;/p&gt;





  &lt;div class=&#34;stroom-theme-dark stroom-menu&#34;&gt;
    
    

      

      
      


      

  
  
  &lt;div class=&#34;stroom-menu-item-background&#34; style=&#34;margin-top: 0px;&#34;&gt;
    
    &lt;div class=&#34;stroom-menu-item &#34; &gt;

      &lt;div class=&#34;stroom-menu-item-text&#34;&gt;Security
      &lt;/div&gt;
        &lt;div class=&#34;stroom-menu-item-arrow&#34;&gt;
          &lt;span class=&#34;stroom-icon inline-svg-button icon-button  &#34; &gt;
    &lt;span class=&#34;face&#34; title=&#34;Arrow right&#34;&gt;&lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; width=&#34;1427.7665&#34; height=&#34;1427.7665&#34; viewBox=&#34;0 0 1427.7665 1427.7665&#34;&gt;&lt;g style=&#34;stroke:currentColor;stroke-width:167.567&#34;&gt;&lt;path d=&#34;m 415.05387,83.70929 c -39.92654,0.4303 -75.41463,48.3887 -40.0468,81.9121 C 567.552,348.69899 760.75555,531.15431 953.73208,713.82391 760.75555,896.49341 567.552,1078.9486 375.00707,1262.0262 c -46.19471,43.7855 28.48812,112.1966 76.0571,67.1681 195.93558,-185.823 392.95261,-370.82479 587.98693,-557.52749 5.6117,-4.8034 10.4633,-10.2473 14.4855,-16.1231 9.643,-12.4844 13.9638,-27.0796 13.6909,-41.7198 0.2729,-14.6402 -4.0479,-29.2354 -13.6909,-41.7198 -4.0222,-5.8758 -8.8738,-11.3198 -14.4855,-16.1231 C 844.01678,469.27821 646.99975,284.27629 451.06417,98.45319 439.91519,87.89979 427.27628,83.57749 415.05387,83.70929 Z&#34;/&gt;&lt;/g&gt;&lt;/svg&gt; &lt;/span&gt;
  &lt;/span&gt;
        &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;

      

      
      
        
      


      

  
  
  &lt;div class=&#34;stroom-menu-item-background&#34; style=&#34;margin-top: 7px;&#34;&gt;
    
    &lt;div class=&#34;stroom-menu-item stroom-menu-item-leaf&#34; &gt;
        &lt;div class=&#34;stroom-menu-item-icon&#34;&gt;
          &lt;span class=&#34;stroom-icon inline-svg-button icon-button  &#34; &gt;
    &lt;span class=&#34;face&#34; title=&#34;Users&#34;&gt;&lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; width=&#34;1792&#34; height=&#34;1792&#34; viewBox=&#34;0 0 1792 1792&#34;&gt;&lt;path style=&#34;fill:var(--icon-colour__orange)&#34; d=&#34;M657 896q-162 5-265 128h-134q-82 0-138-40.5t-56-118.5q0-353 124-353 6 0 43.5 21t97.5 42.5 119 21.5q67 0 133-23-5 37-5 66 0 139 81 256zm1071 637q0 120-73 189.5t-194 69.5h-874q-121 0-194-69.5t-73-189.5q0-53 3.5-103.5t14-109 26.5-108.5 43-97.5 62-81 85.5-53.5 111.5-20q10 0 43 21.5t73 48 107 48 135 21.5 135-21.5 107-48 73-48 43-21.5q61 0 111.5 20t85.5 53.5 62 81 43 97.5 26.5 108.5 14 109 3.5 103.5zm-1024-1277q0 106-75 181t-181 75-181-75-75-181 75-181 181-75 181 75 75 181zm704 384q0 159-112.5 271.5t-271.5 112.5-271.5-112.5-112.5-271.5 112.5-271.5 271.5-112.5 271.5 112.5 112.5 271.5zm576 225q0 78-56 118.5t-138 40.5h-134q-103-123-265-128 81-117 81-256 0-29-5-66 66 23 133 23 59 0 119-21.5t97.5-42.5 43.5-21q124 0 124 353zm-128-609q0 106-75 181t-181 75-181-75-75-181 75-181 181-75 181 75 75 181z&#34;/&gt;&lt;/svg&gt; &lt;/span&gt;
  &lt;/span&gt;
        &lt;/div&gt;

      &lt;div class=&#34;stroom-menu-item-text&#34;&gt;Manage Accounts
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;/div&gt;



&lt;p&gt;from the main menu.&lt;/p&gt;
&lt;p&gt;As a minimum a user account must have a unique identifier that will be used to identify them in Stroom.&lt;/p&gt;
&lt;p&gt;If the user&amp;rsquo;s email address is added then Stroom will be able to email the user to reset their password.
This functionality is configured using the properties starting with this prefix &lt;code&gt;stroom.security.identity.email.&lt;/code&gt;.&lt;/p&gt;
&lt;h3 id=&#34;account-flags&#34;&gt;Account Flags&lt;/h3&gt;
&lt;p&gt;User accounts have a number of flags that can be set by an administrator or automatically by Stroom.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;Enabled&lt;/em&gt; - Enables/disables the account.
A disabled account cannot login.
Useful for disabling a user that is temporarily on leave.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;Locked&lt;/em&gt; - Set when a user has too many failed login attempts (controlled by the property &lt;code&gt;stroom.security.identity.failedLoginLockThreshold&lt;/code&gt;).
Can be un-set by a user with &lt;code&gt;Manage Users&lt;/code&gt; &lt;span class=&#34;glossary-link&#34;&gt;
    &lt;a href=&#34;../../docs/glossary/a/glossary-application-permission&#34;&gt;
      &lt;span&gt;Application permission&lt;/span&gt;
      &lt;i class=&#34;glossary-link-icon fas fa-book fa-sm text-primary&#34;&gt;&lt;/i&gt;
    &lt;/a&gt;&lt;span class=&#34;glossary-tooltip&#34;&gt;
      &lt;span class=&#34;glossary-tooltip-title&#34;&gt;Application permission&lt;/span&gt;
      &lt;span class=&#34;glossary-tooltip-summary&#34;&gt;This is a permission that is not specific to a single document. It applies to all documents or is not related to documents in any way.&lt;/span&gt;&lt;span class=&#34;glossary-tooltip-truncated&#34;&gt;Click to see more details...&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;.
A locked account cannot login.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;Inactive&lt;/em&gt; - Set automatically in one of these cases:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A brand new account has not been used for a duration greater than &lt;code&gt;stroom.security.identity.passwordPolicy.neverUsedAccountDeactivationThreshold&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;An account has not been used for a duration greater than &lt;code&gt;stroom.security.identity.passwordPolicy.unusedAccountDeactivationThreshold&lt;/code&gt;.
An inactive account cannot login.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

      </description>
    </item>
    
  </channel>
</rss>
