> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.1/3.-guide-to-navigation/3.4-users.md).

# 3.4 Users

#### What Is a User in Ztrust?

User in Ztrust is a digital identity that represents a person or entity in the platform; That can:

* Log in to applications
* Be assigned roles (permissions)
* Be part of groups
* Have attributes (e.g. name, email, department)
* Use credentials (passwords, OTP, etc.) for authentication

<figure><img src="/files/YPGARNP4w7pNNPFIr1DT" alt=""><figcaption><p>Fig 3.4.a: List of available users</p></figcaption></figure>

Within the Users section, new users can be generated.

Additionally, you can view or modify various attributes associated with the user accounts.

You can use the search box to find a specific user.

Click the Refresh button to see the latest settings.

<figure><img src="/files/wVvvc4I5lgbRiwSclZTc" alt=""><figcaption><p>Fig 3.4.b: Refresh button to load the newly added or registered users</p></figcaption></figure>

You can also choose how many users you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

<figure><img src="/files/6r006cmRfXB4rrMmrt9P" alt=""><figcaption><p>Fig 3.4.c: Choose how many users you want to display on one screen</p></figcaption></figure>

You have two options for searching users: default search and attribute search.

* Default search: This is the basic search feature where you can search through any part of the data.
* Attribute search: After selecting Attribute search, you'll be prompted to choose the attribute with which you want to search for the user.

<figure><img src="/files/qeruXzKnPLBPJd0pK43t" alt=""><figcaption><p>Fig 3.4.d: Search user based on data or attribute</p></figcaption></figure>

You can choose the specific key and value of the user/users you wish to search for.

<figure><img src="/files/xHQbNQMTZ4s9rzpom7NZ" alt=""><figcaption><p>Fig 3.4.e: Search user based on attribute</p></figcaption></figure>

After entering the Key-Value pair and clicking on the checkmark icon, you will be presented with the users matching that criteria.

You can select a specific user by checking the checkbox next to their name. If you wish to delete one or multiple users simultaneously, select the respective user/users and click on Delete user.

<figure><img src="/files/yBhJdO1SB89X6skmfWOS" alt=""><figcaption><p>Fig 3.4.f: Option to delete user</p></figcaption></figure>

If you want to delete a single user, you can also click on the three dots next to that particular user and select the Delete option.&#x20;

Upon selecting Delete, you will receive a prompt asking for confirmation, as shown below.

<figure><img src="/files/H4xLgjlQPKyZADdQrbHv" alt=""><figcaption><p>Fig 3.4.g: Conformation to delete the user</p></figcaption></figure>

If you wish to remove the user, click on Delete. Otherwise, click Cancel.

#### **Add User**

To generate a new user, click on Add User.

If you need guidance, refer to the steps mentioned under [Creation of User](/ztrust-documentation/user-manual-ztrust-v2.0/admin-manual/creation-of-a-user.md).

<figure><img src="/files/0a3O9mE0cxMRFObp0r6B" alt=""><figcaption><p>Fig 3.4.h: Creation of a new user tab</p></figcaption></figure>

The Username, Email, First Name and Last Name can be edited or modified.

#### **Required User Actions**

<figure><img src="/files/BvfuHbhM3ASoqukxyvVk" alt=""><figcaption><p>Fig 3.4.i: Available required actions</p></figcaption></figure>

It includes the actions which the user needs to perform after logging in.

For example - verify Email sends an email to the user to verify their email address. Update Profile requires the user to update their profile.

#### **Email Verified**

This is a toggle button. When enabled (toggled ON), it enables the verification of a user's email address. When disabled (toggled OFF), the user's email address is not verified.

#### **Username**

This is the name used by the user during creation.

It can also be used for logging into ZTrust.

#### **Email**

The user's provided Email address during registration or in case the user has been created by the Admin. It can also be used for logging into ZTrust.

#### **First Name**

The user's First Name or the First Name provided during registration.

#### **Last Name**

The Last Name provided by the user during registration, or the user's last name.

#### Contact Number

<figure><img src="/files/vKE6MQ8njL04fd6vxUXt" alt=""><figcaption><p>Fig 3.5.j: ContactNumber attribute</p></figcaption></figure>

#### **Groups**

#### **Join Groups**

This setting enables you to join different groups for the specific user.

Clicking on Join Groups will prompt the following:

<figure><img src="/files/wOwVDHOfPYm0JicTyDEY" alt=""><figcaption><p>Fig 3.4.k: List of groups to join user</p></figcaption></figure>

You can search for a specific group using the search box.

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

<figure><img src="/files/OaBXaa5TwKWXm6Mpj1wN" alt=""><figcaption><p>Fig 3.4.l: choose how many groups you want to display on one screen</p></figcaption></figure>

Select the desired group by checking the checkbox next to it. After selecting the group, click on Join.

After clicking on Join, you will be directed to the screen below.

<figure><img src="/files/LxeyIAhHa5Fwqooc9ZrD" alt=""><figcaption><p>Fig 3.4.m: Selecting the group, click on Join</p></figcaption></figure>

You will see the group that you have joined for that specific user.&#x20;

By clicking on the 'x' symbol, you can remove this user from the group.

#### **Create**

If you've entered the details and wish to create a user, click on Create.

#### **Cancel**

If you decide not to create a user, click on Cancel to discard the changes.

After clicking on Create, you will be directed to the screen below.

<figure><img src="/files/UTOYGLBdNdoJHrPd7cYt" alt=""><figcaption><p>Fig 3.4.n: Demo2 user</p></figcaption></figure>

#### **ID**

It is generated automatically once a user is created.&#x20;

#### **Created at**

It indicates the time period when the user was created.

#### **Required User Actions**

<figure><img src="/files/GgA8kSi8x8S2sZtdxYAc" alt=""><figcaption><p>Fig 3.4.o: Available required actions</p></figcaption></figure>

It includes the actions which the user needs to perform after logging in.

For example - verify Email sends an email to the user to verify their email address. Update Profile requires the user to update their profile.

#### **Email Verified**

This is a toggle button. When enabled (toggled ON), it enables the verification of a user's email address. When disabled (toggled OFF), the user's email address is not verified.

#### **Username**

This is the name used by the user during creation.

It can also be used for logging into ZTrust.

#### **Email**

The user's provided Email address during registration or in case the user has been created by the Admin. It can also be used for logging into ZTrust.

#### **First Name**

The user's First Name or the First Name provided during registration.

#### **Last Name**

The Last Name provided by the user during registration, or the user's last name.

#### **Contact Number**

This attribute, created as needed, refers to the user's contact number.

#### **Credentials**

<figure><img src="/files/90zByI9pY3OTrPZS3wMt" alt=""><figcaption><p>Fig 3.4.p: User demo2 with no credentials</p></figcaption></figure>

In the Credentials tab, the administrator can set up the password for the user.&#x20;

Additionally, the Admin user has the ability to delete or reset the user's password.

Upon selecting Set password, you will receive the prompt below.

<figure><img src="/files/zoPz2gh7vS6f3VkwMaNY" alt=""><figcaption><p>Fig 3.4.q: Set the password for demo2</p></figcaption></figure>

#### **Password**

Enter the password that you wish to set for the end user.

#### **Password Confirmation**

Re-enter the password to confirm that it matches the one set previously.

#### **Temporary**

This toggle button, when enabled (toggled ON), requires the user to change the password at the next login.

When toggled OFF, the user is not required to change the password.

You can toggle it ON or OFF according to your requirements.

#### **Save**

After making changes, if you want to save the credentials, click on Save.

Upon clicking Save, you will receive the following prompt asking for confirmation.

<figure><img src="/files/CvORqD9VxK0hto8lmifq" alt=""><figcaption><p>Fig 3.4.r: Conformation to save the password</p></figcaption></figure>

Click on Save password if you want to save the credentials, otherwise click on Cancel.

#### **Cancel**

If you decide not to save the credentials, click on Cancel.

After saving the credentials, you will be presented with the screen below.

<figure><img src="/files/4gKUPdpw2NOASqzMDJTG" alt=""><figcaption><p>Fig 3.4.s: demo2 user with credentials</p></figcaption></figure>

#### **Type**

This indicates the type of credential, such as password or OTP (One-Time Password).

#### **User Label**

This refers to the label assigned by the user to identify the credential when presented as an option during login.

You can assign any value to it that aids in recognizing the credential.

#### **Created at**

It indicates the time period when the user was created.

#### **Data**

This represents the technical details of the credential, which are not confidential.&#x20;

By default, this information is hidden.&#x20;

You can reveal the data for a credential by clicking on Show data…&#x20;

Upon clicking on Show data…, you will be presented with a prompt containing the following details.

<figure><img src="/files/IC4ILWlRGABt96UhyZud" alt=""><figcaption><p>Fig 3.4.t: Password metadata</p></figcaption></figure>

#### **Algorithms**

These are mathematical functions that transform plaintext passwords into unique, fixed-size outputs known as hashes. These hashes are subsequently stored in databases.

#### **hashIterations**

It indicates how many times a password is hashed before being stored in the database.

<figure><img src="/files/0rQ7VSHCkHWc2tM6wVJm" alt=""><figcaption><p>Fig 3.4.u: Option to delete the password</p></figcaption></figure>

#### **Reset password**

<figure><img src="/files/vv2iABcG0t05KqrtKmq7" alt=""><figcaption><p>Fig 3.4.v: Reset password form</p></figcaption></figure>

In the Reset Password section, the Admin user can reset the password for the user.

#### **Password**

In this tab, the Admin can configure the Password for the selected user.

#### **Password Confirmation**

The same Password must be entered again here to ensure accuracy in setting up the password.

#### **Temporary**

When enabled (toggled ON), the user is required to change the password upon the next login. When disabled (OFF), the user is not prompted to change the password on the next login but can do so at their convenience.

#### **Save**

As an Admin, when setting up a password for an end user and providing the necessary details as indicated above, you can save the password by clicking on Save.

Upon clicking Save, you will receive the following confirmation prompt:

<figure><img src="/files/NFSYJoI9QpXp6IieVUsT" alt=""><figcaption><p>Fig 3.4.w: Conformation to reset the password</p></figcaption></figure>

To proceed with resetting the password for the user, select Reset Password. Otherwise, click Cancel to abort the operation.

#### **Delete**

If the credentials are no longer required, choose Delete to remove them.

You can move the credentials up and down (by dragging the rows up and down) as per the priorities.

#### **Role Mapping**

<figure><img src="/files/5ZtsqsFk6Trn17Eq8aF7" alt=""><figcaption><p>Fig 3.4.x: List of avaliables roles</p></figcaption></figure>

You can use the search box to find a specific role.

#### **Hide inherited roles**

Selecting this checkbox hides inherited roles, preventing you from seeing roles inherited from composites. To view inherited roles, simply uncheck this option.

Click the Refresh button to see the latest settings.

<figure><img src="/files/bVBz0IvR2HmKPIiIZtln" alt=""><figcaption><p>Fig 3.4.y: Choose how many roles you want to display on one screen</p></figcaption></figure>

You can also choose how many roles you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

#### **Name**

It includes the list of all the different roles that are already defined in ZTrust.

#### **Inherited**

This pertains to roles explicitly assigned to users and those inherited from composite roles. It can have two values: True (indicating the role is inherited from composites) or False (indicating it is not inherited from any composite role).

#### **Description**

It refers to the description for the role which will aid you in identifying its purpose.

This field can be localized by specifying a substitution variable with ${var-name} strings.

<figure><img src="/files/UUl494PbehewMnpmqLeu" alt=""><figcaption><p>Fig 3.4.z: Option to unassign roles</p></figcaption></figure>

Upon clicking the three dots, you'll encounter the option to unassign the role for that specific user. After selecting Unassign, you will receive the following prompt asking for confirmation.

<figure><img src="/files/9PrTgPWysfuzqY9b0Fb2" alt=""><figcaption><p>Fig 3.4.Aa: Confirmation to remove the role</p></figcaption></figure>

\
Click on Remove to unassign the role, or click on Cancel to keep it assigned.

<figure><img src="/files/Du3nI0grrMLNzLxWAMrG" alt=""><figcaption><p>Fif 3.4.Ab: List of assigned roles </p></figcaption></figure>

You can select the checkbox for the specific role you want to assign with this role. Click on the checkbox to select the role, then click on Assign role.&#x20;

#### **Groups**

<figure><img src="/files/fOKZ2bELvMfRia0XhfPB" alt=""><figcaption><p>Fig 3.4.Ac: Demouser in no groups added</p></figcaption></figure>

It includes Groups in which the user is a member.

To make the user a member of a specific group, select Join Groups.

Clicking on Join Groups will prompt the following:

<figure><img src="/files/LumE5sZGLsz5caX8IoRx" alt=""><figcaption><p>Fig 3.4.Ad: Join demo user in avalible groups</p></figcaption></figure>

You can search for a specific group using the search box.

<figure><img src="/files/ekrumhatO2Jk8bkjb1lP" alt=""><figcaption><p>Fig 3.4.Ae: choose how many groups you want to display on one screen</p></figcaption></figure>

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

<figure><img src="/files/itVcp4dyYtmor322aIWp" alt=""><figcaption><p>Fig 3.4.Af: Select the group to assign the user</p></figcaption></figure>

Select the desired group by checking the checkbox next to it. After selecting the group, click on Join.

After clicking on Join, you will be directed to the screen below.

<figure><img src="/files/kZyrmTo5RElI7gu45Kpk" alt=""><figcaption><p>Fig 3.4.Ag: User is assigned to group</p></figcaption></figure>

You will see the group that you have joined for that specific user.&#x20;

Click the Refresh button to see the latest settings.

#### **Direct membership**

This is useful if the user belongs to a child group.&#x20;

By selecting this checkbox, you can directly see the child group the user is a member of. If the checkbox is unchecked, it will display both the child group and the parent group the user is part of.

\
You can search for a specific group using the search box.

<figure><img src="/files/k6QvGSdpmfWo1MBD6aCD" alt=""><figcaption><p>Fig 3.4.Ah: Choose how many groups you want to display on one screen</p></figcaption></figure>

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

#### **Group membership**

It specifies the name of the group.

#### **Path**

It specifies the path where the group is present.

<figure><img src="/files/AZlfepj0Tdk7BritNztb" alt=""><figcaption><p>Fig 3.4.Ai: Path where the group is present</p></figcaption></figure>

#### **Leave**

If you wish to remove the user from the group, click on Leave.&#x20;

After clicking on Leave, you will receive the following prompt asking for confirmation.

<figure><img src="/files/nMmwCUtqW7PPuF3HDWL9" alt=""><figcaption><p>Fig 3.4.Aj: Confirmation to leave the user from group</p></figcaption></figure>

Click on Leave to remove the user from that group, or click on Cancel to keep them in the group.

To remove the user from multiple groups at once, select each group by clicking the checkbox next to it. Then, click Leave.

<figure><img src="/files/kKtaqP0zFBmTjRe4IcTa" alt=""><figcaption><p>Fig 3.4.Ak: To remove the user from multiple groups at once</p></figcaption></figure>

A confirmation prompt will appear.&#x20;

<figure><img src="/files/eX8HAnooi5sXazpraY6k" alt=""><figcaption><p>Fig 3.4.Al: Confirmation prompt will appear</p></figcaption></figure>

Click on Leave to confirm the removal, or click Cancel to abort.

#### **Consents**

<figure><img src="/files/YnGY1rGEasKUVaBSaOp7" alt=""><figcaption><p>Fig 3.4.Am: User has granted consent to access</p></figcaption></figure>

This tab provides information about the clients to which the user has granted consent to access, including the default client scopes and any additional client scopes granted.

#### **Identity Provider links**

<figure><img src="/files/qaegs54EplQIFPyGhYzn" alt=""><figcaption><p>Fig 3.4.An: Users to connect their accounts with other providers </p></figcaption></figure>

This section enables users to connect their accounts with other providers.

#### Sessions

<figure><img src="/files/HlP91Rg6TX02VG7krDbe" alt=""><figcaption><p>Fig 3.4.Ao: Active sessions tab</p></figcaption></figure>

Under Sessions, the admin can view the clients where this user has an active session along with the following details for each session.

#### **Enabled**

<figure><img src="/files/M9DI8k9kV88SQo28yltR" alt=""><figcaption><p>Fig 3.4.Ap: Option to enable and desable the user</p></figcaption></figure>

When enabled (toggled ON), the user can log in.

If disabled (turned OFF) for any particular user, login access is restricted for that user.

#### **Action**

This refers to the actions that can be performed on a user account, such as Impersonate or Delete.

<figure><img src="/files/vDTOsKlC8WMObR7sozu2" alt=""><figcaption><p>Fig 3.4.Aq: Option to impersonate or delete the user</p></figcaption></figure>

#### **Impersonate**

Clicking on Impersonate allows you to log in as that user.&#x20;

If the user is in the same realm as yours, your current session will be logged out before logging in as that user.

#### **Delete**

The user can be deleted on clicking the Delete button.

<figure><img src="/files/K6iFKBczZODXckwEFpZJ" alt=""><figcaption><p>Fig 3.3.Ar: Conformation to delete the user</p></figcaption></figure>

Upon clicking Delete, you will receive a prompt as depicted above, requesting confirmation. Click Delete to remove that specific user, or click Cancel to retain them.

<br>
