Unless configured otherwise by the System Admin in the Zone Admin panel, any admin can add/edit user data. Otherwise only the Zone Super Admin and System Admin can do so. User data can be entered manually or configured to pull automatically from an LDAP server. In non-LDAP configurations, to add a user click New, enter required and desired data in applicable text box, select or deselect appropriate status and then click Commit. Values for the Role, Group, and Location, and Company fields can be selected from a pull down menu to the right of each field, or entered as free text. The menus are populated with all previous unique values in that field. Before a user is added, the system will check for properly formatted e-mail addresses, and duplicate e-mail and full names, and warn, but allow. It will also check for full names with forbidden file system characters and require edit. User will be warned if entries exceed size limits and then have the option to edit. To modify user data, click on user name, edit data and click Commit. Usernames cannot be edited. To grant zone access to a user, right click on a user in the list and select Grant Access to User. When the user list has been filtered (see below), the context menu will enable the option to grant all users access to the zone, instead of just a single user.
For LDAP configurations new users, except those with third party status, can only be added through LDAP. Click on Update to force refresh from LDAP server. A choice of Partial or Full Update will be given. Selecting Partial Update will only retrieve information about new users in the directory server. Those already defined to VPC will not be updated. Selecting Full Update will cause all users in the directory server, or in a specified group if configured that way, to be updated. Full Update can incur a significant performance hit on the server for very large number of users. For either type, all required fields must be tied to LDAP. All optional fields can be configured to LDAP fields or allow for manual entry. Where manual entry is permitted in certain fields, the process is the same as it is for modifying regular users. Any admin can perform the update function, unless the configuration table entry 'AdminsCanUpateFromLDAP' is set to NO. Then only the System Admin and Zone Super Admin can do so.
Third party users can be entered manually, or an LDAP user can be converted to third party. When a third party user is added manually, an e-mail welcome message can be sent automatically to them if a standard message has been created by the System Admin. After clicking on commit, a panel will open with the standard welcome message and space to customize the message. Files can also be attached to the message. Click on OK to send or Cancel to abort. If welcome e-mail is sent, it will automatically include the username, and it will be followed by another e-mail with the user’s password. Only the System Admin can access the button to edit Third Party Welcome message. Non LDAP users can be imported from a properly formatted Excel spreadsheet. The column headers from left to right are as follows: Username, Fullname, Email, Password, Phone, Pager, Cellphone, Role, Group, Location, Company, ShowVersion, ShowTeams, GetReport, Is Third Party, Expiration Date. User data should be entered starting with row 2. Only the first 4 columns are required fields. ShowVersion, ShowTeams, GetReport, and Is Third Party correspond to check boxes in the table. Enter Yes for check and No for unchecked. No entry means the default value is imported. The default value for ShowVersion, ShowTeams, and GetReport is Yes. The default value for Is third Party is No. If Is Third Party is set to Yes, and third party user management is configured, and no date is entered in Expiration Date column, then the user will be imported as de-activated
If configured this way, all third party users will become de-activated after a set period of time, unless action is taken to extend the period. The default maximum period is 90 calendar days, but this is configurable. When a third party user is created, or the status of a regular LDAP user is changed to third party, the initial activation period will be set at the configured maximum. This can be changed before hitting the commit button by manually entering a new date or selecting from the date picker. If a date beyond the maximum is selected, an error message will appear after commit. The de-activation date can be changed at anytime by selecting the user, editing the date (as long as maximum is not exceeded), and committing. Users can be de-activated immediately by selecting them, clearing the de-activation date and then committing change. Third party users can also be managed by clicking on the Third Party Management button and using the tool. (See Third Party Management).
De-activated users can’t log on to VPC, although their settings will otherwise remain the same for possible re-activation. They will show in gray in admin User panel list, show on Group and Zone Admin user lists, but otherwise not be visible. If the user is part of a group, all actions performed for the group, such as permissions and access to proposals will be done as well for the de-activated user in case it is re-activated. When a third party user expiration date passes, an e-mail will be sent to System Admin.When a user is selected from the list the Send Welcome button is activated, unless it's a third party user that has been de-activated. Any admin can use this to resend welcome message and password e-mails to the selected user. Passwords will only be sent to non-LDAP users. There are different welcome messages for regular vs. third party users. To edit or create either, click on Edit Welcome button and choose desired message type. To remove a user not added through LDAP, click on user name then Remove. Need to confirm before user will be deleted. LDAP users can only be removed by removing them from the applicable group on the LDAP server.
System Admin can select a user and click on Remove from all zones to remove zone access from all zones for the selected user. There will be a warning. No change will be made to proposal access or permissions.
When the users text box is selected and a letter key is hit, the list will scroll to the user
name beginning with that letter. Can list users by full name, username or email. Can filter user list by Role, Group, Location, Company, and any combination thereof. Select filter icon to the right of applicable text box, and select value from pull down menu. Repeat for multiple criteria. Click on filter icon again to de-select. Click on copy icon in user list to copy to another location, and click on print icon to print list.
|