When viewing a user's details, the following information is displayed:
- User name
- User ID
- Email address associated with the user account
- Status, such as Pending, Enabled, or Disabled
- Last login timestamp
- Authentication type, such as Local or External
Additionally, there are five tabs with additional information about that user's account:
- Effective access
- Roles
- Groups
- Sessions
- Audit logs
Effective access
The Effective access tab displays the user's Allow permissions across the platform. If a permission is Deny or Unset, it is not displayed in the list. Similarly, if an Allow permission is overwritten by a Deny permission, it is not displayed.
To view a user's effective access:
- In the list on the Users page, locate the user.
- Select the ellipses in the row and then select View effective access.
To locate a particular access permission, enter the permission name in the search bar.
User's assigned roles
The Roles tab displays all the roles that the user is assigned. From here, you can manage the user's currently assigned roles and add new roles to the user.
The list displays the following information about each role:
- Role name
- Description of the role
- Source, which is how the role is applied to the user. For example, a group membership or directly on the user
To remove a role from the user, select the ellipses in the row. Then select Remove.
You can also remove several roles simultaneously. To do so, check the checkboxes on the left side of each role you want to remove. A bar will be displayed at the top of the list with the number of roles selected. To proceed, select Remove.
Users's group memberships
All of the user's group memberships are displayed on the Groups tab. From here, you can manage the user's group memberships. For instructions on how to add users to and remove users from groups, refer to Adding users to and removing users from groups.
User's sessions
The Sessions tab displays a list of the user's active sessions on the platform with the following details about each session:
- Session ID
- Timestamp
- Source IP
- User agent, such as the web browser, operating system, etc.
If the user has no active sessions, the tab will display the message The user has no active sessions and no data is displayed.
Terminating user sessions
If you have permission to Terminate user sessions, you have the option to terminate the user's active session(s). To terminate a single, specific session, select the Terminate session icon on the right end of the row.
To terminate all of the user's active sessions, select Terminate all sessions.
User audit logs
The Audit logs tab displays a list of actions the user has completed on the platform and its applications, for example, adding a device or deleting a group.
The list displays the following information for each item:
- Timestamp
- Action type, such as Add, Update, Delete
- Application, such as Platform, DDI orchestrator
- Object type
- Address, which is the IP address from which the change was made
You can filter the list by the following parameters: Timestamp, Action type, Application, and Object type.
To view more details about an entry in the audit log, use the arrow on the left side of the row to expand it. These additional details include the following:
- ID for the entry
- Request ID
- Object name
- Object ref
- Event text
- User
- Session ID
- Save comment