How you manage users in the Users app depends on whether your organization uses Single Sign-On (SSO). Without SSO, you create and maintain users directly in the Users app. With SSO, your identity provider is the source of truth, and most user details are read-only in the Users app.
Managed users (no SSO)
If your organization does not use SSO, users are managed directly in the Users app. You add each user, set a sign-in method, and maintain their profile, roles, and campus access in the platform.
For managed users, you can:
- Add and delete users
- Edit profile fields such as first name, last name, and Unique Ext. ID
- Assign roles, Home Location, and campuses
- Reset a user's password
- Enable or disable a user
- Manage a user's multi-factor authentication (MFA) devices
Managed users sign in with an email address and password. The email address serves as the username. For more, see Add a user.
Note: Editing a user's email address is not supported in the Users app for any sign-in method. To change an email address, submit a request.
SSO users
If your organization uses SSO, users sign in through your identity provider rather than with a Kio Cloud password. The identity provider is the source of truth for these users, so the Users app shows their profile details as read-only.
For SSO users, the following are synced from your identity provider and cannot be edited in the Users app:
- Profile fields, such as first name and last name
- Sign-in method
- Roles inherited through SSO groups
- Campus access inherited through SSO groups
The following can still be maintained in the Users app for an SSO user, because your identity provider does not sync them:
- Home Location
- Direct Access roles assigned in the Users app
SSO users do not have a Reset Password button or an enable/disable toggle, and their MFA is managed in your identity provider rather than in Kio Cloud.
Note: SSO integration is configured by the Kontakt.io team. To enable it, submit a request.
SSO groups
Groups in the Users app are either Managed or SSO. SSO groups are synced from your identity provider when users sign in. Membership, roles, and campus assignments for an SSO group are managed in your identity provider and are view-only in the Users app. Through an SSO group, a user can inherit both group membership and the roles assigned to that group.
For a full explanation of group types and inheritance, see About Groups.
Note: User Groups in the Users app are not the same as Groups in the Kio Apps (for example, Staff Groups in Staff Safe). User Groups organize Kio Cloud users for shared roles and campus access (Staff Groups organize badge wearers for alerting).
How to tell which model applies
The Sign-In column on the Users list shows each user's sign-in method. A user maintained entirely in Kio Cloud signs in with a password. A user provisioned through SSO shows an SSO sign-in method, and their synced details appear as view-only on their profile.