User Management in SapphireIMS


 

SapphireIMS facilitates the creation and management of users who would be able to use the system through the user interface which allows addition/editing/removal of users. For each users the personal information including user ID, the full name, e-mail address, Phone Number, Each user is associated with a particular user role to facilitate secured access to the system.

 

SapphireIMS provides interfaces to import user details from existing database systems such as an Human Resource Management System, AD/LDAP server or Excel files thus simplifying the creation of users.

 

A number of reports are available under Reports > IT Automation > User Management which include application usage, Top 10 users etc.

 

Managing Users

 

 

 

 

Note: Deleting an user account is a non-reversible action. The account will be permanently deleted from the system. However accounts imported from an LDAP/AD server cannot be deleted locally. The account has to be deleted on the LDAP/AD server.

 

Reset AD Password

 

Note:1. ‘Reset Password’ tab will be visible only if the setting key ‘Enable/Disable Password Reset Feature’ in ‘Settings > Advanced System Settings > Global Settings’ is enabled by setting as 1.

2. The setting key 'Enable/Disable AD Account Operation Access' in 'Settings > Advanced System Settings > Global Settings' should be set to 1 to enable AD Password Reset.

The lists of users imported from LDAP/AD server into SapphireIMS has a password associated and maintained in the LDAP/AD server. This password can be reset either by the user (Refer Getting Started->Preferences) or by the SapphireIMS administrator. In the case where the SapphireIMS administrator wants to reset the password, the same can be done without having to know the secret question setting. The new password will get updated in the LDAP/AD server.

 

 

 

Unlock User Account

 

User accounts can get locked if invalid password is entered in succession till the limit for invalid tries is reached. The account can be unlocked through self service or by the SapphireIMS administrator.

 

Conflicted Users

 

When importing users from LDAP/AD servers if there is a conflict or the users were not successfully imported, they are listed under 'Conflicted Users'. You can view the user information and decide to either delete the entries or Include the entry in the users list.

 

 

 

Note: You cannot login to SapphireIMS with AD conflicted user name and password.

 

Preferences Configuration

 

SapphireIMS allows the users to modify certain attributes of their profile under User Details section in 'Preferences' (Refer Getting Started->Preferences). These are the Full name, Telephone Number, Mobile Number and e-mail address. Additionally in case the users are imported from an LDAP/AD server, the attributes are updated on the LDAP/AD server also. In order to allow users to change these attributes the administrator has to configure the preferences.

 

Note: To enable the update of LDAP/AD attributes to the LDAP/AD server, the Global Settings 'Enable/Disable updation of AD attributes' should be set to 1. Also the LDAP/AD server configuration should be using SSL for any update of the LDAP/AD server.

 

 

 

 

 

Note: While only a few fields are set-up for enabling preferences, other fields can be added if needed. However this requires changes to the database and you can contact SapphireIMS Support team for the same.

 

Additional User Information

 

This feature allows you to add additional fields while importing users from LDAP.

 

 

 

 

Notes: 1. If the AD attribute is present in LDAP, it is imported else the attribute is displayed as '--' in the user listing.

2. If the 'Visibility' column is checked, the user additional field will appear in the list of fields for selection in asset reports ('Allocate To User fields' list in the 'Select Fields' drop down list box of asset reports)

 

Organization Unit Tree

 

SapphireIMS allows you to group users under organization units. OU helps in managing the access control in SapphireIMS. By segregating users and assets based on OU, access to Service Desk tickets or assets in CMDB can be restricted to IT personnel belonging to that OU.

Follow the steps below to do so.

1. Click on 'Organization Unit Tree' and select the OU to which you want to map the users.

2. Click on 'Map Users' option.

 

 

3. Select the user from the list of users under 'Available Users' and click to move the user to the 'Selected Users' box

4. Click 'Add'.

 

 

Managing Logged-in Users

 

 

Rename User Fields