User Properties
The User properties dialog window is available for every user in the Server Manager. You can access the user properties either by double- or right-clicking a user in the Users area.
Administrators can edit the users in the user properties dialog window. The following tabs are available here:
- General
- Account
- Roles
- Member of
- Active Directory
- Entra ID (formerly Azure AD)
- OIDC
- Passkeys
- Advanced
- API Tokens
The content of each tab is explained below.
General
The General tab includes the following options:
- Full name: Enter the user's first and last name here if different from the actual user name on the server.
- Email: Enter the user's email address.
- Phone: Enter the user's phone number.
- Department: Enter the user's department.
- Description: Here you may add additional information about the user, if required.
Account
In the Account tab you can set the following:
Authentication
You can see here the different types of authentication available for the server users:
- Password Depot credentials
- Active Directory
- Entra ID
- OpenID Connect
- WebAuthn/Passkeys
If you select the authentication via Password Depot credentials, administrators have to define a specific user name and password for each user. Afterwards, they have to share the data with their users. Users can or may change the password for the Enterprise Server login afterwards, if this option is enabled in the Server Manager.
The Active Directory authentication is the so called Integrated Windows Authentication (SSO). It requires a full Active Directory synchronization in the Server Manager so that the users can connect to the Enterprise Server using their Windows credentials. Find detailed information about the Active Directory Synchronization in the Server Manager here.
Using the Entra ID authentication users will have to logon on the Enterprise Server with their Microsoft credentials. This authentication also requires a full Entra ID synchronization in the Server Manager prior to the login of a user. Entra ID users can only be added to the Server Manager through synchronization and not manually. Find detailed information about the Entra ID synchronization in the Server Manager here.
With the OpenID Connect option, your users authenticate via an external identity provider (IdP). Logging in to the Enterprise Server no longer requires separate Password Depot credentials, but instead uses the accounts provided by the IdP. A prerequisite is that the OpenID Connect connection is correctly configured in the Server Manager and the corresponding tenant and client data has been stored there. You can find detailed information about the OpenID Connect import here.
With the WebAuthn/Passkeys option, users log in to the Enterprise Server without a password – for example, using a FIDO2 security key, Windows Hello, or another compatible authenticator. The user’s identity is verified cryptographically, without the need to transmit a traditional password. A prerequisite is that WebAuthn is enabled in the Server Manager and the corresponding passkeys have been registered for the users.
Two-Factor Authentication
- Operation Mode: With this setting you can change the 2FA operation mode individually depending on the user's requirements (Default, Deactivated, TOTP, Email, FIDO2).
Account options
- Account deactivated: If this box is checked, the user's account has been locked temporarily. This may occur if a user has reached the maximum failed login attempts allowed on the server. Uncheck the box to activate the account again and thus, enable the user affected to access and log on on the server again.
- User may not change password: Check this box if you do not want to enable local users changing their password for login on the Enterprise Server. Please note that his option can only be used if a user is accessing Password Depot Enterprise Server via Password Depot credentials authentication.
- User must change password at next logon: Check this box if you want users to be forced changing their password for login on the Enterprise Server next time they want to connect. Changing the password will then be mandatory for the user at the next login in any case. Again, please note that his feature can only be activated for local users but not for Active Directory, Entra ID or OpenID Connect users that have been imported to the Server Manager.
Roles
With version 15, additional server roles were implemented. This way, you can assign specific server roles to single or multiple server users and thus, server administration can now be carried out by multiple users instead of having only one person being responsible for server configuration and administration. Users being assigned an additional server role can access both the Server Manager as well as the Enterprise Server using a client. The following server roles are available:
- Server Administrator: This role grants full access to the server and Server Manager. In general, a server administrator has full access to all databases and entries. In addition to that, they can manage and configure the server and its settings by accessing the Server Manager.
- Database Administrator: A Database Administrator can create new databases on the server and edit already existing ones. This server role enables a user, for example, to change a user's or groups' permissions for databases and entries.
- Account Administrator: An Account Administrator can manage users and groups on the server and, in this context, also add new users and groups to the server, for example.
- Group Administrator: The Group Administrator role allows users to access the Server Manager and manage groups and their users for which they have been granted authorizations under Groups → <Group> → Properties → Managed By.
- Active Directory Operator: An Active Directory Operator can perform Active Directory or Entra ID synchronization in the Server Manager. Please note: This server role requires additional server roles, that is, either Database or Account Administrator. If a user is an Active Directory Operator only, they will not be able to perform Active Directory or Entra ID synchronization in the Server Manager or change any other server settings.
- Event Log Reader: An Event Log Reader can access the server's logs.
- Audit Reader: This server role provides read-only access to the server's tamper-proof audit log. An Audit Reader can open the Audit area in the Server Manager, view, filter, and export the entries it contains (NDJSON/CSV), and verify the integrity of the audit chain using Verify now. The audit data is strictly write-protected – there is neither an edit nor a delete function. This role does not grant access to database contents or key management; it is intended for individuals who require read access and compliance exports for auditing and compliance purposes only.
- Security Officer: This server role is responsible for managing the audit integrity keys. A Security Officer can use Tools → Recovery Keys to issue the recovery code for the audit keyring (audit.key) ("Export Recovery Code…") and, in an emergency, restore the keys on a new computer ("Restore Keys on This Computer…"). This deliberately keeps responsibility for the recoverability of the audit trail separate from the server's other secrets: the audit recovery code can be held by a Security Officer, while the code for the configuration keyring (secure.key) remains reserved for the server administrator (separation of duties). The Security Officer has no insight into the audit log itself — viewing, filtering, exporting and verifying audit records is reserved for the Audit Reader role (and the server administrator).
- Backup Operator: This server role is intended for the management of server backups. Under Tools → Recovery Keys, a Backup Operator has access exclusively to the Restore Keys on This Computer function. Issuing new recovery codes is not available to this role – that is reserved exclusively for the Server Administrator (for the configuration keyring) and the Security Officer (for the audit-trail keyring).
NOTE: Introducing different server roles in the Server Manager with version 15 did also have an impact on the super administrator's account: The latter is now only used for server administration in the Server Manager and thus, the super administrator can only login to the Server Manager but not to the Enterprise Server to access databases. In general, the super administrator's account is not a classic user account anymore and is therefore not a part of the total number of users available on the server.
Member of
You can check here, if the user selected is a group member of one or several server groups. In addition to that, you can add single users to new or other server groups , provided those groups are already available in the Server Manager.
- Add group: Click this button to add a user to a new or other group.
- Delete: Select a group from the list and click Delete afterwards to remove the selected user from the corresponding group.
Active Directory
This tab contains all Active Directory attributes of a user who has been added to the Server Manager through Active Directory synchronization.
- AD Logon Name: Displays a user's user name which is used for the domain login.
- User Principal Name: The User Principal Name displays the name of the Active Directory system user in email format.
- Distinguished Name: Displays a user's correct path in the Active Directory.
- Object GUID: Displays the ID of an Active Directory user which is generated automatically.
NOTE: The information displayed in the tabs called Entra ID or Active Directory is of importance only if Active Directory or Entra ID synchronization is performed in the Server Manager thus, enabling users to login to the server through Integrated Windows Authentication (SSO) or using their Entra ID access data. During synchronization the users' Active Directory or Entra ID attributes will be added to the Server Manager automatically. Therefore, please do not enter here any data manually but instead please let Password Depot Enterprise Server do so during the process of synchronization.
Entra ID
This tab contains all Entra ID attributes of a user who has been added to the Server Manager through Entra ID synchronization.
- User Principal Name: The User Principal Name is displayed if the user has been added to the Server Manager through Entra ID synchronization.
- Object ID: Every Entra ID user is assigned a specific object ID. A user's object ID is also displayed in the Server Manager once the Entra ID synchronization has been completed.
- User Type: Check a user's user type who was imported from Entra ID into the Server Manager. Entra ID has two types of users: members and guests. Members belong to your own organization. A guest can be invited to your organization temporarily, for example if temporary collaboration is required.
OIDC
This tab displays all OpenID Connect attributes of a user who has been added to the Server Manager through OpenID Connect synchronization.
- Username: The username is displayed in case the user has been added to the Server Manager through OpenID Connect synchronization.
- User ID: Every OpenID Connect user is assigned a user ID in case he has been added by OpenID Connect synchronization.
Passkeys
On this tab, the passkeys registered for the user are listed, which can be used for passwordless login to the Enterprise Server.
- Name: Shows the name of the registered passkey.
- Created: Indicates the date and time when the passkey was created or registered for this user.
- Accessed: Shows when this passkey was last used for login or authentication on the Enterprise Server.
- Add passkey: Opens the dialog for registering a new passkey for the selected user.
- Delete: Removes the selected passkey. After deletion, the user can no longer log in to the Enterprise Server using this passkey.
Advanced
The Advanced tab consists of the following part:
- IP address verification
IP address verification
If necessary, enable the Verify IP option. You can assign a Fixed IP address to a user so that any connection attempt by this user with an IP address other than the one specified here will be rejected. This can increase security, but requires the use of static IP addresses. In addition, an IP Range (from...to) can be specified.
API Tokens
In the API Tokens tab, you can manage the API tokens issued for the user that are used to access the REST API. With Password Depot 19.1.0, the new REST API v2.0 was introduced, which among other features supports the generation of long-lived API tokens. These tokens make it possible to authenticate against the REST API without having to transmit a traditional master password – suitable, for example, for service accounts, scheduled tasks, CI/CD pipelines, or monitoring scripts.
Detailed information about the REST API and the use of API tokens can be found in the section on the REST API v2.0.
The following information is displayed for each API token:
- Name: The label assigned to the token at the time of its creation. It helps to identify a token – for example, to keep track of which purpose or which script a token was issued for.
- Scope: Indicates the rights with which the token can be used. Two options are available:
- Client: Allows access to databases, folders, entries, and search – that is, the typical scope of functions available to a client.
- Admin: In addition to the client rights, this scope grants access to all server administration endpoints (user, group, permission, alert, and secret management as well as database management).
- Status: Shows the current state of the token (for example, whether it is active and can be used or whether it can no longer be used).
- Expires: Indicates the expiration date of the token. After this date, the token can no longer be used for authentication.
- Last Used: Shows when the token was last used for authentication against the REST API. If the token has never been used, Never is displayed.
You can manage the API tokens using the following buttons:
- Generate Token: Opens the Generate API Token dialog. Here you can define the following:
- Name: Enter a unique label for the token.
- Scope: Choose whether the token should have the Client or Admin scope.
- Expires in (days): Specify how many days the token should remain valid. The default value is 180 days; values between 1 and 730 days are possible. The resulting expiration date is displayed to the right of the input field.
- Click Generate to create the token. The window Token Generated Successfully then opens with a note indicating that the token is displayed only once at this point and cannot be retrieved afterwards. Click the Copy button to copy the token to the clipboard and store it in a secure location. Click Close to close the dialog.
- Revoke: Sets the selected token to invalid. Before the token is revoked, a confirmation prompt is displayed, indicating that this operation cannot be reversed. Click Yes to revoke the token, or click No to cancel the operation. A revoked token remains visible in the list but can no longer be used for authentication.
- Delete: Removes the selected token completely from the list. This button is only available when the token is no longer active (for example, because it has already been revoked or has expired).
WARNING: The generated token is shown only once in the Token Generated Successfully dialog. Make sure to copy the token at that moment and store it securely. After the dialog has been closed, the token cannot be viewed again.
NOTE: API tokens should not be embedded in source code or checked into version control systems. Always use the minimum required scope (Client, unless administrative functions are needed), and revoke tokens immediately once they are no longer needed.
Return to the Password Depot homepage • Support Center • Legal Notice • Privacy Policy