Users
User administrators can manage users that are authorized to sign in to the portal and the activities that the users can perform.
You can view users in the organization from the Users panel on the Organizations management view. Hover over an icon in the Status column on the Users panel to see details about the status of the user. Hover over an entry in the Last Activity column to see a time stamp for when the activity occurred.
You can update your personal information, change your password, and manage your authentication applications by clicking Account settings from the user-account drop-down menu in the upper-right corner, and then clicking .
Username
The username is the same as the user’s email address. The email address is formatted as {local-part}@{domain}. The maximum length, including the local part and domain, is 320 characters.
The local part is case-sensitive and can contain special characters . + - _ @ , in addition to letters and numeric characters in supported languages.
Email domains
XClarity One portal supports local and corporate user accounts with different email domains.
By default, the email domain of the first organization owner is added to the list of allowed email domains for the organization.
User administrators can only add users with an email domain in the allowed list of domains.
Organization owners can add users with any email domain. You are notified if the email address has a domain that is not currently in the list of allowed email domains. If you choose to continue, you are prompted to add the domain to the list of allowed email domains.
Organization owners can manually add or remove allowed email domains in the organization by clicking the Organization management view and then clicking the Edit icon (
) on the Details card. An email notification is sent to all organization owners when an email domain is added or removed.
Removing an email domain that is used by one more users does not affect existing users’ ability to sign in.
Organization owners
The user that submits the new-organization request becomes an organization owner. Organization owners, identified by the owner icon (), can manage users and configure organization-specific settings. In addition, the first organization owner also has full access to the organization by default, including hub and device administrator roles.
Each organization must have at least one active owner; however, at least two owners is highly recommended for redundancy and security.
Local vs corporate users
User administrators can manually add users to their organization using the portal’s local identity-management system. These are called local users.
Users that sign in using an identity provider are referred to as corporate users.
When an external (corporate) identity provider other than LDAP is configured, user accounts are not created automatically. You must manually add each IDP user to XClarity One and assign the appropriate roles.
When the organization is configured to use an LDAP server, XClarity One uses LDAP user groups to determine which users are allowed to sign in. You must manually create LDAP user groups in XClarity One that match the user-group names defined on the LDAP server. XClarity One automatically creates user accounts for users who sign in through LDAP and belong to one or more of the matching user groups. For more information about LDAP user groups, see User groups.
If an external IDP is configured to use a specific email domain, non-organization owners with that domain can be created in and signed in only through that external IDP. Email domains that are used by an external IDP cannot be used for local users other than organization owners.
When using the XClarity One cloud portal, an email is sent to you to link your corporate and local user accounts.
When using XClarity One on premises and SMTP is not configured, the web interface prompts you to sign in again using your credentials and one-time passcode to link your corporate and local user. Otherwise, an email is sent to you to link the accounts.
After signing in to the corporate IDP, corporate users can access the XClarity One portal without providing additional credentials. In addition, XClarity One requires multifactor authentication by providing a one-time passcode (OTP) from an authenticator application that is connected to XClarity One.
If the corporate IDP is disabled or removed, all corporate users are disabled. Users with local user accounts can still sign in using local XClarity One credentials.
Disabled versus blocked users
A user administrator can disable any users (except themselves) in an organization. A disabled user is prevented from accessing that organization. Disabled users are identified by the Disabled status icon (
) icon on the Users panel.
In certain circumstances, Lenovo can block users in the portal. Blocked users are prevented from accessing all organizations in the XClarity One portal. Blocked users are identified by the Blocked status (
) icon on the Users panel.